TP-Link SR20 ·ÓÉÆ÷ 0dayÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-03-29

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾£º


TP-Link SR20 ÖÇÄܼÒͥ·ÓÉÆ÷


Îó²î¸ÅÊö


ÒòÎó²î±¨¸æÌá½»ºó90ÌìÄÚÈÔδÊÕµ½ÈκλØÓ¦£¬£¬£¬£¬£¬¹È¸èÇå¾²¿ª·¢Ô±Ñ¡Ôñ¹ûÕæ TP-Link SR20 ÖÇÄܼÒͥ·ÓÉÆ÷ÖеÄÒ»¸ö 0day í§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î¿Éµ¼ÖÂλÓÚÍ³Ò»ÍøÂçµÄDZÔÚ¹¥»÷ÕßÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£


TP-Link ·ÓÉÆ÷¾­³£ÒÔ root ȨÏÞÔËÐÐÃûΪ¡°tddp£¨TP-Link ×°±¸µ÷ÊÔЭÒ飩¡±µÄÀú³Ì£¬£¬£¬£¬£¬¶øÕâ¸öÀú³Ì´Ëǰ±»Ö¸°üÀ¨ÆäËü¶à¸öÎó²î¡£¡£¡£¡£¡£¡£¡£¡£


TDDP ÔÊÐíÔÚ×°±¸ÉÏÔËÐÐÁ½ÖÖÀàÐ͵ÄÏÂÁµÚÒ»ÖÖ²»ÒªÇóÈÏÖ¤£¬£¬£¬£¬£¬¶øµÚ¶þÖÖÒªÇóÖÎÀíԱƾ֤¡£¡£¡£¡£¡£¡£¡£¡£


Ò×Êܹ¥»÷µÄ·ÓÉÆ÷̻¶Á˶à¸öµÚÒ»ÖÖÀàÐ͵ÄÏÂÁ¼´²»ÒªÇóÈÏÖ¤µÄÏÂÁ£¬£¬£¬£¬£¬ÆäÖÐÒ»ÖÖÏÂÁî 0X1f¡¢ÇëÇó 0X01¡°ËƺõÊÇΪijÖÖÉèÖÃÑéÖ¤ÉèÖá±£¬£¬£¬£¬£¬ÔÊÐí×¼ºÚ¿Í·¢ËÍÒ»¸öÏÂÁ£¬£¬£¬£¬ÆäÖаüÀ¨Ò»¸öÎļþÃû³Æ¡¢Ò»¸ö·ÖºÅÒÔ¼°²ÎÊýÀ´³õʼ»¯Ê¹ÓÃÀú³Ì¡£¡£¡£¡£¡£¡£¡£¡£


ÕâÑùÖ¸Áî TP-Link ·ÓÉÆ÷½«ÌØÊâ½á¹¹µÄÇëÇóͨ¹ý Trivial File Transfer Protocol (TFTP) ¾ÙÐз¢ËÍ¡£¡£¡£¡£¡£¡£¡£¡£Ò»µ©ÅþÁ¬µ½Ç±ÔÚ¹¥»÷ÕߵĻúе£¬£¬£¬£¬£¬SR20 ÖÇÄÜ·ÓÉÆ÷¡°Í¨¹ý TFTP ÇëÇóÎļþÃû³Æ£¬£¬£¬£¬£¬½«Æäµ¼Èë LUA Ú¹ÊÍÆ÷²¢½«²ÎÊýת´ï¸øËùµ¼ÈëÎļþÖÐµÄ config_test() º¯Êý¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÚ¹ÊÍÆ÷ÒÔ root ȨÏÞÔËÐС£¡£¡£¡£¡£¡£¡£¡£¡±


½Ó×Å£¬£¬£¬£¬£¬ os.execute() ÒªÁ콫ÔÊÐíδ¾­ÈÏÖ¤µÄ¹¥»÷ÕßÒÔ root ȨÏÞÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬£¬´Ó¶øµ¼ÖÂÈκα»¹¥ÏÝµÄ TP-Link SR20 ×°±¸±»ÍêÈ«½ÓÊÜ¡£¡£¡£¡£¡£¡£¡£¡£


©¶´Ê¹ÓÃ


ËäÈ» tddp ÊØ»¤Àú³ÌÖ¼ÔÚ¼àÌýËùÓд«ÈëÁ÷Á¿µÄ½Ó¿Ú£¬£¬£¬£¬£¬µ«ÅäÓÐĬÈÏ·À»ðǽµÄ SR20 ·ÓÉÆ÷½«×èÖ¹¹¥»÷Õß´Ó×°±¸ËùÔÚ¾ÖÓòÍøÒÔÍâµÄµØ·½Ê¹ÓøÃ0day¡£¡£¡£¡£¡£¡£¡£¡£
PoC£ºhttps://pastebin.com/GAzccR95¡£¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚTP-Link ÉÐδ¶Ô´ËÊÂÖÃÆÀ¡£¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/zero-day-tp-link-sr20-router-vulnerability-disclosed-by-google-dev/