Telestar TelnetºóÃÅ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-09-10

¡ñ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-13473 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-13474 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


¡ñÓ°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Bobs Rock Radio

Dabman D10

Dabman i30 Stereo

Imperial i110

Imperial i150

Imperial i200

Imperial i200-cd

Imperial i400

Imperial i450

Imperial i500-bt

Imperial i600


¡ñ·ì϶¸ÅÊö


½üÆÚ £¬Óа²È«×êÑÐÈËÔ±·¢ÏÖ £¬ImperialºÍDabmanϵÁеÄÎïÁªÍøÊÕÒô»ú´æÔÚÈõÃÜÂëȱµã £¬Äܹ»Èù¥»÷ÕßÔ¶³ÌÒÔrootȨÏÞ½øÐз¸·¨½Ó¼û£¨¸ÃÉ豸ÄÚǶLinux BusyBox²Ù×÷ϵͳ£© £¬²¢ÆëÈ«½ÚÔìÉ豸¡£Ö®ºó £¬¹¥»÷Õ߿ɰÑÒѽÚÔìÉ豸²ÎÓë½©Ê¬ÍøÂç £¬ÏòÉ豸·¢ËÍ×Ô½ç˵ÒôƵÁ÷ £¬¼àÌýËùÓÐÊÕÒô»úÐÂÎÅ £¬»¹Äܹ»ÕÒµ½ÊÕÒô»úÒÑÏνÓWiFiµÄÃÜÂë¡£


CVE-2019-13473


¸Ã·ìÏ¶Éæ¼°ÊÕÒô»úÉÏ23¶Ë¿ÚµÄTelnet·þÎñ¡£ÓÉÓÚ¸ÃTelnetd·þÎñʹÓÃÁËÈõÃÜÂ루Ӳ±àÂëÔÚÉ豸ÖУ© £¬Ö»ÓÐͨ¹ýµ¥Ò»µÄÃÜÂ뱩Á¦ÆÆ½â £¬¹¥»÷Õ߾ͿɻñµÃ¶ÔÊÕÒô»ú¼°ÆäÄÚǶ²Ù×÷ϵͳµÄ½Ó¼ûȨÏÞ¡£


ÔÚ²âÊÔÖÐ £¬×êÑÐÈËÔ±°µÊ¾ £¬Ö»ÓÐʹÓÃ×Ô¶¯µÄ¡°ncrack¡±¾ç±¾ £¬¼«¶ÈÖÓÄÚ¾Í¿ÉÆÆ½âÃÜÂë¡£ÖµµÃÒ»ÌáµÄÊÇ £¬É豸µÄÓ²±àÂëÃÜÂëΪ¡°password¡±¡£


ÔڵǼµ½É豸ºó,×êÑÐÈËÔ±¿ÉÄÜÖ±½Ó½Ó¼ûetcĿ¼Ï±ØÒªrootÌØÈ¨ÄÜÁ¦½Ó¼ûµÄ¸÷ÀàÎļþ £¬Ô̺¬º¬ÓÐϵͳÃÜÂëµÄshadowÎļþ £¬Ô̺¬USBÃÜÂëºÍhttpd·þÎñÃÜÂëµÄwifi.cfgÎļþ £¬»¹ÓÐһЩÃô¸ÐµÄÎÞÏßÍøÂçÐÅÏ¢¡£


ƾ¾Ý°²È«×êÑÐÈËÔ±ÖÜÒ»°ä²¼µÄÒ»·Ý»ã±¨ £¬Ä¿Ç°ÎªÖ¹ £¬ËûÃÇ¿ÉÄܽӼûºÍhttpd¡¢TelnetÓйصÄËùÓÐÎļþ £¬»¹Äܹ»¼¤»îftpºÍ̸¡£´Ë±í £¬×êÑÐÈËÔ±»¹·¢ÏÖÁËÒ»¸öÃûΪUIDataµÄõè¾¶ £¬ÆäÖÐÔ̺¬É豸web·þÎñ£¨Ê¢¿ªÔÚ80¶Ë¿ÚºÍ8080¶Ë¿Ú£©µÄËùÓÐÎļþ(¶þ½øÔìÎļþ¡¢xml¡¢Í¼Æ¬¡¢Îı¾ºÍÆäËûÄÚÈÝ)¡£ÎªÁ˽øÐвâÊÔ £¬ÎÒÃDZà×ëÁËһЩÎļþ¼Ó×¢´´½¨ÁËÎļþ²¢Åú¸ÄÁËõè¾¶ £¬ÒÔ±ã²âÊÔÎÒÃÇÊÇ·ñÄÜŤתweb·þÎñµÄÔ´´úÂë¡£×îÖÕÖ¤ÁËÈ»ÎÒÃÇ¿ÉÄÜÆëÈ«½ÚÔìÉ豸µÄÈκÎ×é¼þºÍ·þÎñ¡£


CVE-2019-13474


AirMusic¿Í»§¶Ë´æÔÚµÚ¶þ¸ö·ì϶(CVE-2019-13474) £¬Î´¾­Éí·ÝÑéÖ¤µÄºÅÁîÖ´ÐС£


×êÑÐÈËÔ±°µÊ¾ £¬Í¨¹ýÆ»¹ûIOSÉϵÄÊÕÒô»úÀûÓà £¬½áºÏ¶Ë¿ÚɨÃèÁ˾Ö £¬·¢ÏÖAirMusic¿Í»§¶Ë¿ÉÄÜͨ¹ý80ºÍ8080¶Ë¿ÚµÄhttpd·þÎñÀ´·¢ËͺͽӹܺÅÁî¡£¾­¹ýÒ»¸öÓ×ʱµÄ²âÊÔ £¬×îÖÕ×êÑÐÈËԱȷ¶¨¿ÉÄÜͨ¹ýweb·þÎñÏò¿Í»§¶Ë·¢ËͺÅÁî¡£


ÒÔÉÏÕâÁ½¸ö·ì϶һµ©×éºÏÆðÀ´ £¬¿ÉÄÜ»áÒý·¢Ò»ÏµÁжñÒâÍøÂç»î¶¯¡£¹¥»÷ÕßÄܹ»¼àÌý¡¢¸ü¸Ä¹ã²¥Á÷»ò·¢ËÍ×Ô¼ºµÄʵʱÐÂÎÅ»òÒôƵÎļþ¡£¹¥»÷Õß»¹¿É°ÑÉ豸ˢгɽ©Ê¬ÍøÂçÖеÄÒ»Ô± £¬ÀûÓÃËüµÄweb·þÎñ´«µÝÀÕË÷Èí¼þºÍ¶ñÒⲡ¶¾¡£


×êÑÐÈËÔ±³Æ £¬ÕâЩ·ì϶¡°Ó°ÏìÁËImperialºÍDabmanÆ·ÅÆµÄ´óÁ¿ÍøÂçÊÕÒô»ú¡±¡£ËûÃǰµÊ¾ £¬ÓÐ100¶àÍǫ̀É豸´¦ÓÚΣÏÕÖ®ÖС£Ä¿Ç°ÕâЩÊÕÒô»úÓÉTelestar Digital GmbHÔڵ¹úÏúÊÛ £¬²¢ÔÚÑÇÂíÑ·(Amazon)ºÍeBayÉÏÃæ¶ÔÈ«Çò½øÐÐÏúÊÛ £¬¿í·ºÀûÓÃÓÚ¼ÒÍ¥ºÍ°ì¹«»·¾³¡£Telstar°µÊ¾ £¬½ñºóÉ豸½«ÖÕ³¡Ê¹ÓÃTelnet·þÎñ £¬²¢ÎªÏÖÓÐÉ豸°ä²¼°²È«²¹¶¡¡£


¡ñ·ì϶ÑéÖ¤


POC£ºhttps://www.vulnerability-lab.com/get_content.php?id=2183

POCÊÓÆµ£ºhttps://youtu.be/odyB15MRY3Q¡£


¡ñ½¨¸´½¨Òé


Ôì×÷ÉÌtelestar digital gmbhÌṩÁËÒ»¸öȫеĸüа汾 £¬ÒÔ½â¾öÆäÖеķì϶¡£ËùÓÐi&dϵÁвúÆ·¡£½¨Ò龡¿ì×°ÖøüÐÂÒÔÈ·±£Êý×Ö°²È«¡£


ÊÖ¶¯¸üв½Ö裺


1.½«É豸ÉèÖÃΪ³ö³§ÉèÖÃ

2.Ñ¡Ôñ˵»°

3.¹Ø¹ØÉ豸

4.´ò¿ªÉ豸

5.ÍøÂçÉèÖÃ

6.ÆÚ´ý¡°ÐÂÈí¼þ¡±ÐÂÎÅ

7.°´¡°È·¶¨¡±ÆðÍ·¸üÐÂ

8.¸üа汾£ºTN81HH96-g102h-g103 ** a * -fb21a-3624¡£


¡ñ²Î¿¼Á´½Ó

https://www.zdnet.com/article/critical-vulnerabilities-impact-over-a-million-iot-radio-devices/