TP-Link SR20 ·ÓÉÆ÷ 0day·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-03-29

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾£º


TP-Link SR20 ÖÇÄܼÒͥ·ÓÉÆ÷


·ì϶¸ÅÊö


Òò·ì϶»ã±¨Ìá½»ºó90ÌìÄÚÈÔδÊÕµ½ÈκλØÓ¦£¬¹È¸è°²È«¿ª·¢Ô±Ñ¡Ôñ¹«¿ª TP-Link SR20 ÖÇÄܼÒͥ·ÓÉÆ÷ÖеÄÒ»¸ö 0day ËÁÒâ´úÂëÖ´Ðзì϶¡£¸Ã·ì϶¿Éµ¼ÖÂλÓÚÍ³Ò»ÍøÂçµÄDZÔÚ¹¥»÷ÕßÖ´ÐÐËÁÒâºÅÁî¡£


TP-Link ·ÓÉÆ÷ʱʱÒÔ root ȨÏÞÔËÐÐÃûΪ¡°tddp£¨TP-Link É豸µ÷ÊÔºÍ̸£©¡±µÄ¹ý³Ì£¬¶øÕâ¸ö¹ý³Ì´Ëǰ±»Ö¸Ô̺¬ÆäËü¶à¸ö·ì϶¡£


TDDP ÔÊÐíÔÚÉ豸ÉÏÔËÐÐÁ½ÖÖÀàÐ͵ĺÅÁµÚÒ»ÖÖ²»ÒªÇóÈÏÖ¤£¬¶øµÚ¶þÖÖÒªÇóÖÎÀíԱƾ֤¡£


Ò×Êܹ¥»÷µÄ·ÓÉÆ÷¶³öÁ˶à¸öµÚÒ»ÖÖÀàÐ͵ĺÅÁ¼´²»ÒªÇóÈÏÖ¤µÄºÅÁ£¬ÆäÖÐÒ»ÖÖºÅÁî 0X1f¡¢ÒªÇó 0X01¡°ËƺõÊÇΪijÖÖÅäÖÃÑéÖ¤ÉèÖá±£¬ÔÊÐí×¼ºÚ¿Í·¢ËÍÒ»¸öºÅÁÆäÖÐÔ̺¬Ò»¸öÎļþÃû³Æ¡¢Ò»¸ö·ÖºÅÒÔ¼°²ÎÊýÀ´³õʼ»¯ÀûÓùý³Ì¡£


ÕâÑùÖ¸Áî TP-Link ·ÓÉÆ÷½«ÌØÊâ»ú¹ØµÄÒªÇóͨ¹ý Trivial File Transfer Protocol (TFTP) ½øÐз¢ËÍ¡£Ò»µ©Ïνӵ½Ç±ÔÚ¹¥»÷ÕߵĻúе£¬SR20 ÖÇÄÜ·ÓÉÆ÷¡°Í¨¹ý TFTP ÒªÇóÎļþÃû³Æ£¬½«Æäµ¼Èë LUA Ú¹ÊÍÆ÷²¢½«²ÎÊý´«µÝ¸øËùµ¼ÈëÎļþÖÐµÄ config_test() º¯Êý¡£¸ÃÚ¹ÊÍÆ÷ÒÔ root ȨÏÞÔËÐС£¡±


½Ó×Å£¬ os.execute() ²½Ö轫ÔÊÐíδ¾­ÈÏÖ¤µÄ¹¥»÷ÕßÒÔ root ȨÏÞÖ´ÐÐËÁÒâºÅÁ´Ó¶øµ¼ÖÂÈκα»¹¥Ï嵀 TP-Link SR20 É豸±»ÆëÈ«ÊÕÊÜ¡£


©¶´ÀûÓÃ


¹ÌÈ» tddp ÊØ»¤¹ý³ÌÖ¼ÔÚ¼àÌýËùÓд«ÈëÁ÷Á¿µÄ½Ó¿Ú£¬µ«ÅäÓÐĬÈÏ·À»ðǽµÄ SR20 ·ÓÉÆ÷½«×èÖ¹¹¥»÷Õß´ÓÉ豸µØµã¾ÖÓòÍøÒÔ±íµÄ´¦ËùÀûÓøÃ0day¡£
PoC£ºhttps://pastebin.com/GAzccR95¡£


½¨¸´½¨Òé


ĿǰTP-Link ÉÐδ¶Ô´ËÊÂÖÃÆÀ¡£


²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/zero-day-tp-link-sr20-router-vulnerability-disclosed-by-google-dev/