Release DateJan 05, 2012 |
Severityhigh |
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems |
DescriptionThis indicates an attack attempt against a Remote Code Execution vulnerability in CTEK SkyRouter 4200 and 4300.This is due tp how the filters for user inputs fail to properly sanitize the parameter value that is passed to "cfg_ethping.cgi". An attacker may include shell commands by supplying an injection string through the URL. |
Affected ProductsCTEK SkyRouter 4200 and 4300 |
Recommended ActionsCurrently we are not aware of any vendor supplied patches for this issue. |
Coverage IPS
VCM |
Reference/shttp://dev.metasploit.com/redmine/issues/5610 |