TP-Link SR20 ·ÓÉÆ÷ 0dayÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-03-29Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾£º
TP-Link SR20 ÖÇÄܼÒͥ·ÓÉÆ÷
Îó²î¸ÅÊö
ÒòÎó²î±¨¸æÌá½»ºó90ÌìÄÚÈÔδÊÕµ½ÈκλØÓ¦£¬£¬£¬£¬£¬¹È¸èÇå¾²¿ª·¢Ô±Ñ¡Ôñ¹ûÕæ TP-Link SR20 ÖÇÄܼÒͥ·ÓÉÆ÷ÖеÄÒ»¸ö 0day í§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î¿Éµ¼ÖÂλÓÚÍ³Ò»ÍøÂçµÄDZÔÚ¹¥»÷ÕßÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£
TP-Link ·ÓÉÆ÷¾³£ÒÔ root ȨÏÞÔËÐÐÃûΪ¡°tddp£¨TP-Link ×°±¸µ÷ÊÔÐÒ飩¡±µÄÀú³Ì£¬£¬£¬£¬£¬¶øÕâ¸öÀú³Ì´Ëǰ±»Ö¸°üÀ¨ÆäËü¶à¸öÎó²î¡£¡£¡£¡£¡£¡£¡£¡£
TDDP ÔÊÐíÔÚ×°±¸ÉÏÔËÐÐÁ½ÖÖÀàÐ͵ÄÏÂÁµÚÒ»ÖÖ²»ÒªÇóÈÏÖ¤£¬£¬£¬£¬£¬¶øµÚ¶þÖÖÒªÇóÖÎÀíԱƾ֤¡£¡£¡£¡£¡£¡£¡£¡£
Ò×Êܹ¥»÷µÄ·ÓÉÆ÷̻¶Á˶à¸öµÚÒ»ÖÖÀàÐ͵ÄÏÂÁ¼´²»ÒªÇóÈÏÖ¤µÄÏÂÁ£¬£¬£¬£¬£¬ÆäÖÐÒ»ÖÖÏÂÁî 0X1f¡¢ÇëÇó 0X01¡°ËƺõÊÇΪijÖÖÉèÖÃÑéÖ¤ÉèÖá±£¬£¬£¬£¬£¬ÔÊÐí×¼ºÚ¿Í·¢ËÍÒ»¸öÏÂÁ£¬£¬£¬£¬ÆäÖаüÀ¨Ò»¸öÎļþÃû³Æ¡¢Ò»¸ö·ÖºÅÒÔ¼°²ÎÊýÀ´³õʼ»¯Ê¹ÓÃÀú³Ì¡£¡£¡£¡£¡£¡£¡£¡£
ÕâÑùÖ¸Áî TP-Link ·ÓÉÆ÷½«ÌØÊâ½á¹¹µÄÇëÇóͨ¹ý Trivial File Transfer Protocol (TFTP) ¾ÙÐз¢ËÍ¡£¡£¡£¡£¡£¡£¡£¡£Ò»µ©ÅþÁ¬µ½Ç±ÔÚ¹¥»÷ÕߵĻúе£¬£¬£¬£¬£¬SR20 ÖÇÄÜ·ÓÉÆ÷¡°Í¨¹ý TFTP ÇëÇóÎļþÃû³Æ£¬£¬£¬£¬£¬½«Æäµ¼Èë LUA Ú¹ÊÍÆ÷²¢½«²ÎÊýת´ï¸øËùµ¼ÈëÎļþÖÐµÄ config_test() º¯Êý¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÚ¹ÊÍÆ÷ÒÔ root ȨÏÞÔËÐС£¡£¡£¡£¡£¡£¡£¡£¡±
½Ó×Å£¬£¬£¬£¬£¬ os.execute() ÒªÁ콫ÔÊÐíδ¾ÈÏÖ¤µÄ¹¥»÷ÕßÒÔ root ȨÏÞÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬£¬´Ó¶øµ¼ÖÂÈκα»¹¥ÏÝµÄ TP-Link SR20 ×°±¸±»ÍêÈ«½ÓÊÜ¡£¡£¡£¡£¡£¡£¡£¡£
©¶´Ê¹ÓÃ
ËäÈ» tddp ÊØ»¤Àú³ÌÖ¼ÔÚ¼àÌýËùÓд«ÈëÁ÷Á¿µÄ½Ó¿Ú£¬£¬£¬£¬£¬µ«ÅäÓÐĬÈÏ·À»ðǽµÄ SR20 ·ÓÉÆ÷½«×èÖ¹¹¥»÷Õß´Ó×°±¸ËùÔÚ¾ÖÓòÍøÒÔÍâµÄµØ·½Ê¹ÓøÃ0day¡£¡£¡£¡£¡£¡£¡£¡£
PoC£ºhttps://pastebin.com/GAzccR95¡£¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚTP-Link ÉÐδ¶Ô´ËÊÂÖÃÆÀ¡£¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/zero-day-tp-link-sr20-router-vulnerability-disclosed-by-google-dev/


¾©¹«Íø°²±¸11010802024551ºÅ