¡¾·ì϶¹«¸æ¡¿CVE-2020-29583 ZyxelÓ²±àÂëÍ´´¦·ì϶

°ä²¼¹¦·ò 2021-01-04

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2020-29583

ʱ   ¼ä

2021-01-04

Àà   ÐÍ


µÈ   ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


 

0x01 ·ì϶ÏêÇé

image.png

Zyxel£¨ºÏÇڿƼ¼£©Êǹú¼Ê³ÛÃûµÄÍøÂç¿í´øÏµÍ³¼°½â¾ö¹æ»®µÄ¹©¸øÉÌ¡£Ä¿Ç°£¬È«ÇòÓг¬¹ý100000̨Zyxel·À»ðǽ¡¢VPNÍø¹ØºÍ½Ó¼ûµã½ÚÔìÆ÷¡£

2020Äê12ÔÂ23ÈÕ£¬Zyxel°ä²¼°²È«²¼¸æ£¬Æä·À»ðǽºÍAP½ÚÔìÆ÷ÖдæÔÚÒ»¸ö°²È«·ì϶£¨CVE-2020-29583£©£¬ÆäCVSSÆÀ·Ö7.8¡£

Zyxel·À»ðǽºÍAP½ÚÔìÆ÷ÖÐÔ̺¬Ò»¸ö¡° zyfwp¡¹ØÊ»§£¬¸ÃÕÊ»§¿Éͨ¹ýFTP×Ô¶¯¸üй̼þ¡£ÓÉÓÚ¸ÃÕË»§µÄÃÜÂë²»³É¸ü¸Ä£¬²¢ÇÒÄܹ»Ôڹ̼þÖÐÒÔÃ÷ÎÄ´ó¾Ö£¬¹¥»÷ÕßÄܹ»ÀûÓøÃÕÊ»§ÒÔÖÎÀíԱȨÏ޵Ǽ¡£

$ ssh zyfwp@192.168.1.252

Password: Pr*******Xp

Router> show users current

No: 1

  Name: zyfwp

  Type: admin

(...)

Router>

 

Ó°ÏìÁìÓò£º

¸ß¼¶Íþв·À»¤£¨ATP£©ÏµÁУ¨ÖØÒªÓÃ×÷·À»ðǽ£©

ͳһ°²È«Íø¹Ø£¨USG£©ÏµÁУ¨ÓÃ×÷»ìºÏ·À»ðǽºÍVPNÍø¹Ø£©

USG FLEXϵÁУ¨ÓÃ×÷»ìºÏ·À»ðǽºÍVPNÍø¹Ø£©

VPNϵÁУ¨ÓÃ×÷VPNÍø¹Ø£©

NXCϵÁУ¨ÓÃ×÷WLAN½ÓÈëµã½ÚÔìÆ÷£©

 

0x02 ´ëÖý¨Òé

Ŀǰ£¬ZyxelÒѾ­°ä²¼ÁË´Ë·ì϶µÄ²¿ÃŰ²È«¸üУ¬NXCϵÁеIJ¹¶¡Ô¤¼Æ½«ÓÚ2021Äê4Ô°䲼£¬½¨Òé²Î¿¼Ï±í¸üÐÂÖÁ×îа汾£º

ÊÜÓ°Ïì²úÆ·

²¹¶¡

·À»ðǽ

ATPϵÁÐÔÚÔËÐй̼þZLD V4.60

2020Äê12ÔµÄZLD V4.60²¹¶¡1

USGϵÁÐÔËÐй̼þZLD V4.60

2020Äê12ÔµÄZLD V4.60²¹¶¡1

USG FLEXϵÁÐÔËÐй̼þZLD V4.60

2020Äê12ÔµÄZLD V4.60²¹¶¡1

ÔËÐй̼þZLD V4.60µÄVPNϵÁÐ

2020Äê12ÔµÄZLD V4.60²¹¶¡1

AP½ÚÔìÆ÷

NXC2500

2021Äê4ÔµÄV6.10 Patch1

NXC5500

2021Äê4ÔµÄV6.10 Patch1

 

ÏÂÔØÁ´½Ó£º

https://www.zyxel.com/support/download_landing.shtml

 

0x03 ²Î¿¼Á´½Ó

https://www.zyxel.com/support/CVE-2020-29583.shtml

https://securityaffairs.co/wordpress/112877/iot/secret-backdoor-zyxel-devices.html?

https://www.eyecontrol.nl/blog/undocumented-user-account-in-zyxel-products.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29583

 

0x04 ¹¦·òÏß

2020-12-23  Zyxel°ä²¼°²È«²¼¸æ

2021-01-04  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png