»ªË¶Â·ÓÉÆ÷¿çÕ¾¾ç±¾¹¥»÷Îó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-10-26

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-18287£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


¸ÃÎó²îÓ°ÏìÁË»ªË¶RT-AC58U v3.0.0.4.380_6516·ÓÉÆ÷¡£¡£¡£¡£


Îó²î¸ÅÊö


»ªË¶RT-AC58U·ÓÉÆ÷ÊÇ̨Í廪˶µçÄԹɷÝÓÐÏÞ¹«Ë¾ËùÉè¼ÆÑз¢µÄ¼ÒÍ¥ÎÞÏß·ÓÉÆ÷£¬£¬£¬ £¬£¬ÊÇ»ªË¶¹Ù·½Ðû²¼µÄÊ׿î¸ßͨËĺË˫ƵÎÞÏß·ÓÉÆ÷¡£¡£¡£¡£
Çå¾²Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬ £¬£¬ÔÚ»ªË¶RT-AC58U·ÓÉÆ÷Öб£´æ¿çÕ¾¾ç±¾¹¥»÷Îó²î¡£¡£¡£¡£ÆÊÎöÅú×¢£¬£¬£¬ £¬£¬¸ÃÎó²îÔÊÐíÔ¶³Ì¹¥»÷ÕßÏò×°±¸×¢Èëí§ÒâWeb»òHTML¾ç±¾£¬£¬£¬ £¬£¬µ¼ÖÂLogout.asp, Main_Login.asp, apply.cgi, clients.asp, disk.asp, disk_utility.asp, or internet.aspµÈÒ³Ãæ¾ùÊܵ½Ó°Ïì¡£¡£¡£¡£
º£ÄÚ̻¶ÔÚ»¥ÁªÍøµÄ¸ÃÎó²îÏà¹ØÍøÂç×ʲúÂþÑÜͼ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Îó²îÑéÖ¤


POC£º

https://github.com/remix30303/AsusLeak


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼½â¾öÉÏÊöÎó²îµÄ¹Ì¼þ¸üУ¬£¬£¬ £¬£¬½¨ÒéÏà¹ØÓû§ÊµÊ±¼ì²é¸üС£¡£¡£¡£
»¹Î´Ðû²¼Ïà¹ØÎó²îµÄ²¹¶¡£¬£¬£¬ £¬£¬Çë¹Ø×¢¹ÙÍø¸üУºhttps://www.asus.com/Microsite/2015/networks/routerfirmware_update/
±ðµÄ£¬£¬£¬ £¬£¬½¨ÒéÏà¹ØÓû§Ó¦½ÓÄɵįäËûÇå¾²·À»¤²½·¥ÈçÏ£º
£¨1£©×î´óÏ޶ȵØïÔÌ­ËùÓпØÖÆÏµÍ³×°±¸ºÍ/»òϵͳµÄÍøÂç̻¶£¬£¬£¬ £¬£¬²¢È·±£ÎÞ·¨´ÓInternet»á¼û¡£¡£¡£¡£
£¨2£©¶¨Î»·À»ðǽ·À»¤µÄ¿ØÖÆÏµÍ³ÍøÂçºÍÔ¶³Ì×°±¸£¬£¬£¬ £¬£¬²¢½«ÆäÓëÓªÒµÍøÂç¸ôÀë¡£¡£¡£¡£

£¨3£©µ±ÐèÒªÔ¶³Ì»á¼ûʱ£¬£¬£¬ £¬£¬ÇëʹÓÃÇå¾²ÒªÁìÈçÐéÄâרÓÃÍøÂ磨VPN£©£¬£¬£¬ £¬£¬ÒªÊìϤµ½VPN¿ÉÄܱ£´æµÄÎó²î£¬£¬£¬ £¬£¬Ð轫VPN¸üе½×îа汾¡£¡£¡£¡£


²Î¿¼Á´½Ó


http://www.cnvd.org.cn/flaw/show/CNVD-2018-21251
https://nvd.nist.gov/vuln/detail/CVE-2018-18287#