TP-Link SR20 ·ÓÉÆ÷ 0dayÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-03-29Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾£º
TP-Link SR20 ÖÇÄܼÒͥ·ÓÉÆ÷
Îó²î¸ÅÊö
ÒòÎó²î±¨¸æÌá½»ºó90ÌìÄÚÈÔδÊÕµ½ÈκλØÓ¦£¬£¬£¬£¬¹È¸èÇå¾²¿ª·¢Ô±Ñ¡Ôñ¹ûÕæ TP-Link SR20 ÖÇÄܼÒͥ·ÓÉÆ÷ÖеÄÒ»¸ö 0day í§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²î¿Éµ¼ÖÂλÓÚÍ³Ò»ÍøÂçµÄDZÔÚ¹¥»÷ÕßÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£
TP-Link ·ÓÉÆ÷¾³£ÒÔ root ȨÏÞÔËÐÐÃûΪ¡°tddp£¨TP-Link ×°±¸µ÷ÊÔÐÒ飩¡±µÄÀú³Ì£¬£¬£¬£¬¶øÕâ¸öÀú³Ì´Ëǰ±»Ö¸°üÀ¨ÆäËü¶à¸öÎó²î¡£¡£¡£¡£¡£¡£
TDDP ÔÊÐíÔÚ×°±¸ÉÏÔËÐÐÁ½ÖÖÀàÐ͵ÄÏÂÁµÚÒ»ÖÖ²»ÒªÇóÈÏÖ¤£¬£¬£¬£¬¶øµÚ¶þÖÖÒªÇóÖÎÀíԱƾ֤¡£¡£¡£¡£¡£¡£
Ò×Êܹ¥»÷µÄ·ÓÉÆ÷̻¶Á˶à¸öµÚÒ»ÖÖÀàÐ͵ÄÏÂÁ¼´²»ÒªÇóÈÏÖ¤µÄÏÂÁ£¬£¬£¬£¬ÆäÖÐÒ»ÖÖÏÂÁî 0X1f¡¢ÇëÇó 0X01¡°ËƺõÊÇΪijÖÖÉèÖÃÑéÖ¤ÉèÖá±£¬£¬£¬£¬ÔÊÐí×¼ºÚ¿Í·¢ËÍÒ»¸öÏÂÁ£¬£¬£¬ÆäÖаüÀ¨Ò»¸öÎļþÃû³Æ¡¢Ò»¸ö·ÖºÅÒÔ¼°²ÎÊýÀ´³õʼ»¯Ê¹ÓÃÀú³Ì¡£¡£¡£¡£¡£¡£
ÕâÑùÖ¸Áî TP-Link ·ÓÉÆ÷½«ÌØÊâ½á¹¹µÄÇëÇóͨ¹ý Trivial File Transfer Protocol (TFTP) ¾ÙÐз¢ËÍ¡£¡£¡£¡£¡£¡£Ò»µ©ÅþÁ¬µ½Ç±ÔÚ¹¥»÷ÕߵĻúе£¬£¬£¬£¬SR20 ÖÇÄÜ·ÓÉÆ÷¡°Í¨¹ý TFTP ÇëÇóÎļþÃû³Æ£¬£¬£¬£¬½«Æäµ¼Èë LUA Ú¹ÊÍÆ÷²¢½«²ÎÊýת´ï¸øËùµ¼ÈëÎļþÖÐµÄ config_test() º¯Êý¡£¡£¡£¡£¡£¡£¸ÃÚ¹ÊÍÆ÷ÒÔ root ȨÏÞÔËÐС£¡£¡£¡£¡£¡£¡±
½Ó×Å£¬£¬£¬£¬ os.execute() ÒªÁ콫ÔÊÐíδ¾ÈÏÖ¤µÄ¹¥»÷ÕßÒÔ root ȨÏÞÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬´Ó¶øµ¼ÖÂÈκα»¹¥ÏÝµÄ TP-Link SR20 ×°±¸±»ÍêÈ«½ÓÊÜ¡£¡£¡£¡£¡£¡£
©¶´Ê¹ÓÃ
ËäÈ» tddp ÊØ»¤Àú³ÌÖ¼ÔÚ¼àÌýËùÓд«ÈëÁ÷Á¿µÄ½Ó¿Ú£¬£¬£¬£¬µ«ÅäÓÐĬÈÏ·À»ðǽµÄ SR20 ·ÓÉÆ÷½«×èÖ¹¹¥»÷Õß´Ó×°±¸ËùÔÚ¾ÖÓòÍøÒÔÍâµÄµØ·½Ê¹ÓøÃ0day¡£¡£¡£¡£¡£¡£
PoC£ºhttps://pastebin.com/GAzccR95¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚTP-Link ÉÐδ¶Ô´ËÊÂÖÃÆÀ¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/zero-day-tp-link-sr20-router-vulnerability-disclosed-by-google-dev/