Cisco Small Business RV320ºÍRV325Îó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-01-28

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1652£¬£¬£¬ £¬£¬ £¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬ £¬£¬ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.2£¬£¬£¬ £¬£¬ £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-1653£¬£¬£¬ £¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬£¬ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬ £¬£¬ £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì¹æÄ£


ÊÜÓ°Ïì²úÆ·£º

CVE-2019-1652

ʹÓÃ1.4.2.15°æ±¾ÖÁ1.4.2.19°æ±¾¹Ì¼þµÄCisco Small Business RV320ºÍRV325

CVE-2019-1653

ʹÓÃ1.4.2.15°æ±¾ÖÁ1.4.2.17°æ±¾¹Ì¼þµÄCisco Small Business RV320ºÍRV325


Îó²î¸ÅÊö


Cisco Small Business RV320ºÍRV325¶¼ÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÆóÒµ¼¶Â·ÓÉÆ÷¡£¡£¡£¡£¡£¡£


¿ËÈÕ£¬£¬£¬ £¬£¬ £¬Ë¼¿ÆÎªÂ·ÓÉÆ÷ÐͺŠRV320 ºÍ RV325 Ðû²¼¸üУ¬£¬£¬ £¬£¬ £¬ÐÞ¸´ÁËÒ»¸öÏÂÁî×¢ÈëÎó²î (CVE-2019-1652) ºÍÒ»¸öÐÅÏ¢×ß©Îó²î (CVE-2019-1653)£¬£¬£¬ £¬£¬ £¬ÕâÁ½¸öÎó²î¾ùλÓÚ·ÓÉÆ÷µÄ web ÖÎÀí½Ó¿ÚÖС£¡£¡£¡£¡£¡£±»ÆØÎó²îÇÒ POCºÍEXP ÒÑÐû²¼£¬£¬£¬ £¬£¬ £¬µ¼Ö¹¥»÷ÕßÄܹ»É¨ÃèÒ×Êܹ¥»÷µÄ×°±¸²¢ÍêÈ«¿ØÖÆËüÃÇ¡£¡£¡£¡£¡£¡£¸ÅÊöÈçÏ£º


CVE-2019-1652

»ùÓÚWebµÄÖÎÀí½çÃæ±£´æÏÂÁî×¢ÈëÎó²î£¬£¬£¬ £¬£¬ £¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓÐ׼ȷµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÖÆµÄHTTP POSTÇëÇóʹÓøÃÎó²îÒÔrootȨÏÞÔڵײãLinux shellÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

CVE-2019-1653

»ùÓÚWebµÄÖÎÀí½çÃæ±£´æÐÅϢй¶Îó²î£¬£¬£¬ £¬£¬ £¬¸ÃÎó²îÔ´ÓÚ³ÌÐò¶ÔURLsÖ´ÐÐÁ˹ýʧµÄ»á¼û¿ØÖÆ¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýHTTP»òHTTPSЭÒéÅþÁ¬ÊÜÓ°ÏìµÄ×°±¸²¢ÇëÇóURLsʹÓøÃÎó²î¼ìË÷Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£


Îó²îʹÓÃ


ÏÖÔÚ£¬£¬£¬ £¬£¬ £¬Îó²îµÄPOCºÍEXPÒѹûÕæ£º

CVE-2019-1652

POC: https://cxsecurity.com/issue/WLB-2019010236

EXP: https://github.com/0x27/CiscoRV320Dump

CVE-2019-1653

POC: https://cxsecurity.com/issue/WLB-2019010235

EXP: https://github.com/0x27/CiscoRV320Dump


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£º

CVE-2019-1652

Çë¸üÐÂÖÁ1.4.2.20°æ±¾¡£¡£¡£¡£¡£¡£

CVE-2019-1653

Çë¸üÐÂÖÁ1.4.2.19°æ±¾¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://cxsecurity.com/issue/WLB-2019010236

https://cxsecurity.com/issue/WLB-2019010235

https://github.com/0x27/CiscoRV320Dump

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-info

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-inject