TP-Link SR20 ·ÓÉÆ÷ 0dayÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-03-29

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬ £¬£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾£º


TP-Link SR20 ÖÇÄܼÒͥ·ÓÉÆ÷


Îó²î¸ÅÊö


ÒòÎó²î±¨¸æÌá½»ºó90ÌìÄÚÈÔδÊÕµ½ÈκλØÓ¦£¬£¬ £¬£¬£¬£¬¹È¸èÇå¾²¿ª·¢Ô±Ñ¡Ôñ¹ûÕæ TP-Link SR20 ÖÇÄܼÒͥ·ÓÉÆ÷ÖеÄÒ»¸ö 0day í§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£ ¡£¡£¡£¸ÃÎó²î¿Éµ¼ÖÂλÓÚÍ³Ò»ÍøÂçµÄDZÔÚ¹¥»÷ÕßÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£ ¡£¡£¡£


TP-Link ·ÓÉÆ÷¾­³£ÒÔ root ȨÏÞÔËÐÐÃûΪ¡°tddp£¨TP-Link ×°±¸µ÷ÊÔЭÒ飩¡±µÄÀú³Ì£¬£¬ £¬£¬£¬£¬¶øÕâ¸öÀú³Ì´Ëǰ±»Ö¸°üÀ¨ÆäËü¶à¸öÎó²î¡£¡£¡£ ¡£¡£¡£


TDDP ÔÊÐíÔÚ×°±¸ÉÏÔËÐÐÁ½ÖÖÀàÐ͵ÄÏÂÁµÚÒ»ÖÖ²»ÒªÇóÈÏÖ¤£¬£¬ £¬£¬£¬£¬¶øµÚ¶þÖÖÒªÇóÖÎÀíԱƾ֤¡£¡£¡£ ¡£¡£¡£


Ò×Êܹ¥»÷µÄ·ÓÉÆ÷̻¶Á˶à¸öµÚÒ»ÖÖÀàÐ͵ÄÏÂÁ¼´²»ÒªÇóÈÏÖ¤µÄÏÂÁ£¬£¬ £¬£¬£¬£¬ÆäÖÐÒ»ÖÖÏÂÁî 0X1f¡¢ÇëÇó 0X01¡°ËƺõÊÇΪijÖÖÉèÖÃÑéÖ¤ÉèÖá±£¬£¬ £¬£¬£¬£¬ÔÊÐí×¼ºÚ¿Í·¢ËÍÒ»¸öÏÂÁ£¬ £¬£¬£¬£¬ÆäÖаüÀ¨Ò»¸öÎļþÃû³Æ¡¢Ò»¸ö·ÖºÅÒÔ¼°²ÎÊýÀ´³õʼ»¯Ê¹ÓÃÀú³Ì¡£¡£¡£ ¡£¡£¡£


ÕâÑùÖ¸Áî TP-Link ·ÓÉÆ÷½«ÌØÊâ½á¹¹µÄÇëÇóͨ¹ý Trivial File Transfer Protocol (TFTP) ¾ÙÐз¢ËÍ¡£¡£¡£ ¡£¡£¡£Ò»µ©ÅþÁ¬µ½Ç±ÔÚ¹¥»÷ÕߵĻúе£¬£¬ £¬£¬£¬£¬SR20 ÖÇÄÜ·ÓÉÆ÷¡°Í¨¹ý TFTP ÇëÇóÎļþÃû³Æ£¬£¬ £¬£¬£¬£¬½«Æäµ¼Èë LUA Ú¹ÊÍÆ÷²¢½«²ÎÊýת´ï¸øËùµ¼ÈëÎļþÖÐµÄ config_test() º¯Êý¡£¡£¡£ ¡£¡£¡£¸ÃÚ¹ÊÍÆ÷ÒÔ root ȨÏÞÔËÐС£¡£¡£ ¡£¡£¡£¡±


½Ó×Å£¬£¬ £¬£¬£¬£¬ os.execute() ÒªÁ콫ÔÊÐíδ¾­ÈÏÖ¤µÄ¹¥»÷ÕßÒÔ root ȨÏÞÖ´ÐÐí§ÒâÏÂÁ£¬ £¬£¬£¬£¬´Ó¶øµ¼ÖÂÈκα»¹¥ÏÝµÄ TP-Link SR20 ×°±¸±»ÍêÈ«½ÓÊÜ¡£¡£¡£ ¡£¡£¡£


©¶´Ê¹ÓÃ


ËäÈ» tddp ÊØ»¤Àú³ÌÖ¼ÔÚ¼àÌýËùÓд«ÈëÁ÷Á¿µÄ½Ó¿Ú£¬£¬ £¬£¬£¬£¬µ«ÅäÓÐĬÈÏ·À»ðǽµÄ SR20 ·ÓÉÆ÷½«×èÖ¹¹¥»÷Õß´Ó×°±¸ËùÔÚ¾ÖÓòÍøÒÔÍâµÄµØ·½Ê¹ÓøÃ0day¡£¡£¡£ ¡£¡£¡£
PoC£ºhttps://pastebin.com/GAzccR95¡£¡£¡£ ¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚTP-Link ÉÐδ¶Ô´ËÊÂÖÃÆÀ¡£¡£¡£ ¡£¡£¡£


²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/zero-day-tp-link-sr20-router-vulnerability-disclosed-by-google-dev/