CVE-2020-12695 | UPnPºÍ̸CallStranger·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-06-09

0x00 ·ì϶¸ÅÊö


CVE   ID

CVE-2020-12695

ʱ    ¼ä

2020-06-09

Àà    ÐÍ

µÈ    ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



ͨÓü´²å¼´Óã¨Universal Plug and Play £¬¼ò³ÆUPnP£©ÊÇÓÉÊ¢¿ªÏνӻù½ð»á£¨OCF£©ÖÎÀíµÄÒ»Ì×ÍøÂçºÍ̸¡£¸ÃºÍ̸µÄÖ¸±êÊÇʹ¼ÒÍ¥ÍøÂ磨Êý¾Ý¹²Ïí¡¢Í¨Ñ¶ºÍÓéÀÖ£©ºÍ¹«Ë¾ÍøÂçÖеĸ÷ÀàÉ豸¿ÉÄÜÏ໥ÎÞ·ìÏνÓ £¬²¢¼ò»¯ÓйØÍøÂçµÄʵÏÖ¡£UPnPͨ¹ý½ç˵ºÍ°ä²¼»ùÓÚÊ¢¿ª¡¢ÒòÌØÍøÍ¨Ñ¶ÍøºÍ̸³ß¶ÈµÄUPnPÉ豸½ÚÔìºÍ̸À´ÊµÏÖÕâÒ»Ö¸±ê¡£

2019Äê12Ô £¬Ò»Î»Ãû½ÐYunus?adirciµÄ°²È«¹¤³ÌʦÔÚÕâÏΪ±é¼°µÄ¼¼ÊõÖз¢ÏÖÁËÒ»¸ö·ì϶£¨CVE-2020-12695£© £¬¶¨ÃûΪCallStranger¡£ÔÚÊýÊ®ÒÚ¸öUPNPÉ豸Öз¢ÏÖµÄCallStranger·ì϶¿Éµ¼ÖÂÊý¾Ýй¶£¨¼´±ãÄúÓÐDLP/Ììǵ°²È«É豸£©»òɨÃèÄúµÄÍøÂç £¬ÉõÖÁµ¼ÖÂÄúµÄÍøÂç²Î¼ÓDDoS¹¥»÷¡£¸Ã·ì϶ÓÉUPnP SUBSCRIBEº¯ÊýÖеıêÍ·Öµ»Øµ÷ÒýÆð £¬¹¥»÷ÕßÄܹ»»ú¹ØÒ»¸öº¬ÓÐÌåʽÃýÎóµÄ±êÍ·Öµ»Øµ÷µÄTCPÊý¾Ý°ü·¢Ë͵½Ô¶¶ËÉ豸 £¬À´ÀûÓû¥ÁªÍøÉÏÖ§³ÖUPnPºÍ̸µÄÖÇÄÜÉ豸 £¬ÀýÈçÉãÏñ»ú £¬DVR £¬´òÓ¡»ú £¬Â·ÓÉÆ÷µÈ¡£¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶½øÐÐÒÔϲÙ×÷£º

? ÈÆ¹ýDLPºÍÍøÂ簲ȫÉ豸¿ÉÇÔÈ¡Êý¾Ý £»

? ʹÓÃÊý°ÙÍò¸öÃæÏòInternetµÄUPnPÉ豸×÷Ϊ·Å´óµÄ·´ÉäTCP DDoS/SYN FloodÔ´ £»

? ´ÓÃæÏòInternetµÄUPnPÉ豸ɨÃèÄÚ²¿¶Ë¿Ú¡£

¸Ã·ì϶ӰÏìÁìÓò´ó £¬Ê¹ÓÃshodanɨÃè·¢ÏÖԼĪÓÐ545Íǫ̀¿ªÆôUPnPÖ°ÄܵÄÉ豸Ïνӵ½»¥ÁªÍø £¬ÕâЩÉ豸ÈÝÒ׳ÉΪÎïÁªÍø½©Ê¬ÍøÂçºÍAPT×éÖ¯µÄ¹¥»÷Ö¸±ê¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾




?adirci°µÊ¾ £¬ËûÈ¥ÄêÔøÍ¨ÖªOCF £¬¸Ã×éÖ¯ÒÑÓÚ2020Äê4ÔÂ17ÈÕ¸üÐÂÁËUPnPºÍ̸¹æ·¶¡£ÓÉÓÚÕâÊÇÒ»¸öºÍ̸·ì϶ £¬¹©¸øÉÌ¿ÉÄܱØÒªºÜ³¤¹¦·òÄÜÁ¦Ìṩ²¹¶¡·¨Ê½¡£

ĿǰÒѾ­È·ÈϵÄÊÜÓ°ÏìµÄÁбíÈçÏ£º

Xbox One- OS Version 10.0.19041.2494

ADB TNR-5720SX Box (TNR-5720SX/v16.4-rc-371-gf5e2289 UPnP/1.0 BH-upnpdev/2.0)

Asus ASUS Media Streamer

Asus Rt-N11

Belkin WeMo

Broadcom ADSL Modems

Canon Canon SELPHY CP1200 Printer

Cisco X1000 - (LINUX/2.4 UPnP/1.0 BRCM400/1.0)

Cisco X3500 - (LINUX/2.4 UPnP/1.0 BRCM400/1.0)

D-Link DVG-N5412SP WPS Router (OS 1.0 UPnP/1.0 Realtek/V1.3)

EPSON EP, EW, XP Series (EPSON_Linux UPnP/1.0 Epson UPnP SDK/1.0)

HP Deskjet, Photosmart, Officejet ENVY Series (POSIX, UPnP/1.0, Intel MicroStack/1.0.1347)

Huawei HG255s Router - Firmware HG255sC163B03 (ATP UPnP Core)

NEC AccessTechnica WR8165N Router ( OS 1.0 UPnP/1.0 Realtek/V1.3)

Philips 2k14MTK TV - Firmware TPL161E_012.003.039.001

Samsung UE55MU7000 TV - Firmware T-KTMDEUC-1280.5, BT - S

Samsung MU8000 TV

Siemens CNE1000 Camera

Sony Media Go Media application

Stream What You Hear Stream What You Hear

Toshiba TCC-C1 Media Device

TP-Link Archer C50

Trendnet TV-IP551W

Ubiquiti UniFi Controller

ZTE ZXV10 W300

ZTE H108N

Zyxel AMG1202-T10B


0x02 ´ëÖý¨Òé


1. ÈôÊÇûÓÐÒµÎñ/¼¼ÊõµÄÐèÒª £¬½¨Ò鹨¹Øµ½InternetµÄUPnP¶Ë¿Ú £»

2. ½¨Òé×è¶ÏSUBSCRIBEºÍNOTIFY HTTPÊý¾Ý°ü £»

3. ²é³­ÈÕÖ¾ £¬È·ÈÏÊÇ·ñÓÐÈËʹÓô˷ì϶¡£

´Ë±í £¬×êÑÐÈËÔ±ÒѾ­°ä²¼ÁËPoC £¬Óû§Äܹ»ÓÃÀ´È·¶¨ÆäÖÇÄÜÉ豸ÊÇ·ñÈÝÒ×Êܵ½CallStranger·ì϶µÄ¹¥»÷¡£

https://github.com/yunuscadirci/CallStranger


0x03 ÓйØÐÂÎÅ


https://www.zdnet.com/article/callstranger-vulnerability-lets-attacks-bypass-security-systems-and-scan-lans/#ftag=RSSbaffb68


0x04 ²Î¿¼Á´½Ó


https://callstranger.com/

https://github.com/yunuscadirci/CallStranger

https://kb.cert.org/vuls/id/339275


0x05 ¹¦·òÏß


2020-06-08 ·ì϶¹«¿ª

2020-06-09 VSRC°ä²¼·ì϶¹«¸æ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾