Davolink DVW-3200N·ÓÉÆ÷¸ßΣ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-08-02

·ì϶±àºÅºÍ¼¶±ð


CVE-2018-10618  ³§ÉÌ×ÔÆÀ£º9.8   CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾£º


DVW-3200N version < 1.00.06


²»ÊÜÓ°ÏìµÄ°æ±¾£º


DVW-3200N version 1.00.06


·ì϶¸ÅÊö


7ÔÂ31ÈÕ£¬Davolink DVW-3200N ·ÓÉÆ÷±»ÆØ³ö1¸ö¸ßΣ·ì϶£¨CVE-2018-10618£© ¡£¸Ã·ÓÉÆ÷ÌìÉúÈÝÒ×±»ÆÆ½âµÄÈõÃÜÂ룬ÔÊÐíÔ¶³Ì¹¥»÷Õß»ñÈ¡É豸µÄÃÜÂë ¡£


Davolink DVW-3200N ·ÓÉÆ÷µÄ¶Ë¿Ú88ÉÏÓеǼÃÅ»§£¬½Ó¼ûÊÜÃÜÂë± £»¤£¬µ«ÃÜÂëÔÚµÇÂ¼Ò³ÃæµÄHTMLÖÐÊÇÓ²±àÂëµÄ ¡£·ÖÎöÒ³Ãæ´úÂ룬һ¸öÃûΪ¡°clickApply¡±µÄº¯Êý£¬ÆäÖÐÔ̺¬³ß¶Èbase 64±àÂëÖеÄÃÜÂë ¡£


·ì϶ÀûÓÃ


·ì϶ÀûÓôúÂ룺https://cxsecurity.com/issue/WLB-2018070219 ¡£


½¨¸´½¨Òé


Davolink¹Ù·½Îª¸ÃÉ豸ÌṩÁËÒ»¸öеĹ̼þ°æ±¾£¬Äܹ»´ÓÒÔÏÂÁ´½ÓÏÂÔØ£ºhttp://www.davolink.co.kr/sys/bbs/board.php?bo_table=0403&wr_id=50 ¡£


²Î¿¼Á´½Ó


http://www.davolink.co.kr/sys/bbs/board.php?bo_table=0403&wr_id=50


https://ics-cert.us-cert.gov/advisories/ICSA-18-212-01


https://cxsecurity.com/issue/WLB-2018070219