CVE-2017-14000

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
05/10/2017
Last modified:
20/04/2025

Description

An Improper Authentication issue was discovered in Ctek SkyRouter Series 4200 and 4400, all versions prior to V6.00.11. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access the application without authenticating.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ctekproducts:skyrouter_z4200_firmware:*:*:*:*:*:*:*:* 6.00.05 (including)
cpe:2.3:h:ctekproducts:skyrouter_z4200:-:*:*:*:*:*:*:*
cpe:2.3:o:ctekproducts:skyrouter_z4400_firmware:*:*:*:*:*:*:*:* 6.00.05 (including)
cpe:2.3:h:ctekproducts:skyrouter_z4400:-:*:*:*:*:*:*:*