CVE-2017-14000: Ctekproducts Skyrouter z4200 Firmware

Critical severity, CVSS 9.4. EPSS: 2.3% chance of exploitation in the next 30 days.

An Improper Authentication issue was discovered in Ctek SkyRouter Series 4200 and 4400, all versions prior to V6.00.11. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access the application without authenticating.

Affected products

  • Ctekproducts Skyrouter z4200 Firmware: up to and including 6.00.05
  • Ctekproducts Skyrouter z4400 Firmware: up to and including 6.00.05

Published 2017-10-05. Last modified 2026-06-17.