Verizon Fios Quantum Gateway·ÓÉÆ÷¶à¸ö·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-04-10·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-3915£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.5£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-3916£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.5£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
·ì϶¸ÅÊö
×îÐÂ×êÑз¢ÏÖVerizon Fios Quantum Gateway·ÓÉÆ÷´æÔÚ¶à¸ö·ì϶¡£ÈôÊDZ»ÀûÓã¬ÕâЩ·ì϶½«Ê¹¹¥»÷Õ߯ëÈ«½ÚÔì·ÓÉÆ÷²¢²é¿´ÓëÆäÓйصÄËùÓÐÄÚÈÝ¡£
·ÓÉÆ÷²àÃæÓÐÒ»¸öÌùÖ½¡£ÎªÃ¿¸ö¿Í»§Ìṩ·ÖÆçµÄÎÞÏßÍøÂçÃû³Æ£¬ÎÞÏßÃÜÂëºÍÖÎÀíÔ±ÃÜÂë¡£ÕâЩ·ìÏ¶ÖØÒªÝÓÈÆÖÎÀíÔ±ÃÜÂ룬¶ø²»ÊÇÄúÓÃÓÚÏνÓWi-FiµÄÃÜÂë¡£ÖÎÀíÔ±ÃÜÂëÓÃÓÚVerizon¿Í»§µÇ¼·ÓÉÆ÷ÒÔÖ´ÐнçËµÍøÂçµÄ¸÷À๤×÷¡£·ì϶Ô̺¬£º
CVE-2019-3914 - ¾¹ýÉí·ÝÑéÖ¤µÄÔ¶³ÌºÅÁî×¢Èë
Äܹ»Í¨¹ýΪӵÓо«ÐÄÉè¼ÆµÄÖ÷»úÃûµÄÍøÂç¶ÔÏóÔö³¤·À»ðǽ½Ó¼û½ÚÔì¹æ¶¨À´´¥·¢´Ë·ì϶¡£±ØÐë¶ÔÉ豸µÄÖÎÀíWebÀûÓ÷¨Ê½½øÐÐÉí·ÝÑéÖ¤ÄÜÁ¦Ö´ÐкÅÁî×¢Èë¡£ÔÚ´óÎÞÊýÇé¿öÏ£¬Ö»ÓÐÓµÓб¾µØÍøÂç½Ó¼ûȨÏ޵Ĺ¥»÷ÕßÄÜÁ¦ÀûÓô˷ì϶¡£µ«ÊÇ£¬ÈôÊÇÆôÓÃÔ¶³ÌÖÎÀí£¬Ôò»ùÓÚInternetµÄ¹¥»÷ÊÇ¿ÉÐеģ¬ËüĬÈÏÊǽûÓõġ£
ÀýÈ磬ÈôÊÇÔö³¤Ö÷»úÃûΪ¡°`whoami`¡±µÄÍøÂç¶ÔÏ󣨰ÑÎÈ·´ÒýºÅ£©£¬²¢ÇҴ˶ÔÏóÓÃÓÚ·À»ðǽ½Ó¼û½ÚÔì¹æ¶¨£¬Ôò½«Ö´ÐÓ×®whoami¡¯ºÅÁî¡£
CVE-2019-3915 - µÇ¼³Á²¥
CVE-2019-3916 - ÃÜÂëSaltй¶
·ì϶ÑéÖ¤
ĿǰÒÑÓÐPoC£ºhttps://github.com/tenable/poc/blob/master/verizon/verizon_g1100_cmd_injection.py£¬ËüÄܹ»Ê¹ÓÃÃ÷ÎÄÃÜÂë»ò×÷ΪºÅÁîÐвÎÊýÔö³¤µÄ¹þÏ£Öµ¡£Ñ¡ÔñÈκβ½Öè³ÇÊе¼Ö³ɹ¦µÇ¼·ÓÉÆ÷µÄWeb½çÃæ¡£ÀûÓóɹ¦ÈçÏÂͼ£º

½¨¸´½¨Òé
Verizon°ä²¼Á˹̼þ°æ±¾02.02.00.13À´½¨¸´ÕâЩ·ì϶¡£
²Î¿¼Á´½Ó
https://www.tenable.com/blog/verizon-fios-quantum-gateway-routers-patched-for-multiple-vulnerabilities
https://www.bleepingcomputer.com/news/security/verizon-fixes-bugs-allowing-full-control-of-fios-quantum-router/


¾©¹«Íø°²±¸11010802024551ºÅ