Realtek Wi-Fi¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-02-07

0x00 ·ì϶¸ÅÊö

Realtek RTL8195AMÊÇÒ»¿î¸ß¶È¼¯³ÉµÄµ¥Ð¾Æ¬£¬ÓµÓе͹¦ºÄ»úÔ죬¼«¶ÈÊʺÏÀûÓÃÓÚIoT£¨ÎïÁªÍø£©¡£

2021Äê02ÔÂ06ÈÕ£¬ÒÔÉ«ÁÐÎïÁªÍø°²È«¹«Ë¾VdooµÄ×êÑÐÈËÔ±Åû¶ÁËÔÚRealtek RTL8195A Wi-FiÄ£¿éÖз¢ÏÖµÄ6¸ö°²È«·ì϶£¬¹¥»÷Õß¿ÉÄÜÀûÓÃÕâЩ·ì϶À´»ñµÃrootÓû§µÄ½Ó¼ûȨÏÞ²¢½ÚÔìÉ豸µÄÎÞÏßͨѶ¡£Ö»¹ÜĿǰÕâЩ·ì϶Òѱ»½¨¸´£¬µ«Ê¹ÓÃRealtek RTL8195A Wi-FiÄ£¿éµÄǶÈëʽÉ豸½«Â¶³öÔÚÔ¶³Ì¹¥»÷µÄ·çÏÕÖС£

0x01 ·ì϶ÏêÇé

image.png

 

RTL8195A оƬ֧³ÖWEP¡¢WPAºÍWPA2Éí·ÝÑé֤ģʽ¡£×êÑÐÈËÔ±°µÊ¾£¬ Wi-FiÄ£¿éµÄWPA2ËÄ´ÎÎÕÊÖ»úÔìÔÚÈÏ֤ʱÈÝÒ×´æÔÚ²Ö¿âÒç³öºÍÔ½½ç¶ÁÈ¡ÎÊÌâ¡£

´Ë±í£¬Õâ´Î·¢Ïֵķì϶»¹»áÓ°ÏìÆäËüÄ£¿é£¬ÈçRTL8711AM¡¢RTL8711AFºÍRTL8710AF¡£ÆäÖÐ×îÑϳÁµÄÊÇÒ»¸ö²Ö¿âÒç¶Âí½Å£¨¸ú×ÙΪCVE-2020-9395£©£¬Ëü¿ÉÄܵ¼ÖÂÉ豸ºÍÄ£¿éµÄͨѶÆëÈ«±»½ÚÔì¡£¸Ã·ì϶ÎÞÐè֪·Wi-FiÍøÂçÃÜÂ루PSK£©Ò²¿É±»ÀûÓá£

ÔÚÎÞÐè֪·Wi-FiÍøÂçÃÜÂ루PSK£©µÄÇé¿öÏ£¬¹¥»÷ÕßÒ²Äܹ»Í¨¹ýÀûÓÃCVE-2020-25853ºÍCVE-2020-25857µ¼Ö»ؾø·þÎñ¡£ÈôÊǹ¥»÷ÕßÖªÂ·ÍøÂçµÄPSK£¬ÔòÄܹ»Í¨¹ýÀûÓÃCVE-2020-25854¡¢CVE-2020-25855ºÍCVE-2020-25856Ô¶³ÌÖ´ÐдúÂë»òµ¼Ö»ؾø·þÎñ¡£

±¾´ÎÅû¶µÄ·ì϶ÈçÏ£º

²úÆ·

CVE

ÀàÐÍ

ÆÀ¼¶

Ó°ÏìÁìÓò

Realtek   RTL8195AM¡¢RTL8711A¡¢RTL8711AFºÍRTL8710AF

CVE-2020-9395

»ùÓÚ²Ö¿âµÄ»º³åÇøÒç³ö

¸ßΣ

< 2.0.6

Realtek   RTL8195A Wi-FiÄ£¿é

CVE-2020-25853

Ô½½ç¶ÁÈ¡

ÖÐΣ

< 2.0.8

CVE-2020-25854

»ùÓÚ²Ö¿âµÄ»º³åÇøÒç³ö

CVE-2020-25855

CVE-2020-25856

CVE-2020-25857

 

0x02 ´ëÖý¨Òé

ĿǰÓйطì϶Òѱ»½¨¸´£¬½¨ÒéÉý¼¶ÖÁ2.0.8»ò¸ü¸ß°æ±¾¡£

ÏÂÔØÁ´½Ó£º

https://github.com/ambiot/amb1_arduino

 

0x03 ²Î¿¼Á´½Ó

https://www.realtek.com/en/products/communications-network-ics/item/rtl8195am

https://securityaffairs.co/wordpress/114280/security/realtek-rtl8195a-flaws.html?

https://www.amebaiot.com/en/ameba-arduino-getting-started/

https://nvd.nist.gov/vuln/detail/CVE-2020-9395

 

0x04 ¹¦·òÏß

2021-02-06  Vdoo¹«¿ªÅû¶·ì϶

2021-02-07  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png