TP-Link SR20 ·ÓÉÆ÷ 0dayÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-03-29

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾£º


TP-Link SR20 ÖÇÄܼÒͥ·ÓÉÆ÷


Îó²î¸ÅÊö


ÒòÎó²î±¨¸æÌá½»ºó90ÌìÄÚÈÔδÊÕµ½ÈκλØÓ¦£¬£¬£¬£¬¹È¸èÇå¾²¿ª·¢Ô±Ñ¡Ôñ¹ûÕæ TP-Link SR20 ÖÇÄܼÒͥ·ÓÉÆ÷ÖеÄÒ»¸ö 0day í§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²î¿Éµ¼ÖÂλÓÚÍ³Ò»ÍøÂçµÄDZÔÚ¹¥»÷ÕßÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£


TP-Link ·ÓÉÆ÷¾­³£ÒÔ root ȨÏÞÔËÐÐÃûΪ¡°tddp£¨TP-Link ×°±¸µ÷ÊÔЭÒ飩¡±µÄÀú³Ì£¬£¬£¬£¬¶øÕâ¸öÀú³Ì´Ëǰ±»Ö¸°üÀ¨ÆäËü¶à¸öÎó²î¡£¡£¡£¡£¡£¡£


TDDP ÔÊÐíÔÚ×°±¸ÉÏÔËÐÐÁ½ÖÖÀàÐ͵ÄÏÂÁµÚÒ»ÖÖ²»ÒªÇóÈÏÖ¤£¬£¬£¬£¬¶øµÚ¶þÖÖÒªÇóÖÎÀíԱƾ֤¡£¡£¡£¡£¡£¡£


Ò×Êܹ¥»÷µÄ·ÓÉÆ÷̻¶Á˶à¸öµÚÒ»ÖÖÀàÐ͵ÄÏÂÁ¼´²»ÒªÇóÈÏÖ¤µÄÏÂÁ£¬£¬£¬£¬ÆäÖÐÒ»ÖÖÏÂÁî 0X1f¡¢ÇëÇó 0X01¡°ËƺõÊÇΪijÖÖÉèÖÃÑéÖ¤ÉèÖá±£¬£¬£¬£¬ÔÊÐí×¼ºÚ¿Í·¢ËÍÒ»¸öÏÂÁ£¬£¬£¬ÆäÖаüÀ¨Ò»¸öÎļþÃû³Æ¡¢Ò»¸ö·ÖºÅÒÔ¼°²ÎÊýÀ´³õʼ»¯Ê¹ÓÃÀú³Ì¡£¡£¡£¡£¡£¡£


ÕâÑùÖ¸Áî TP-Link ·ÓÉÆ÷½«ÌØÊâ½á¹¹µÄÇëÇóͨ¹ý Trivial File Transfer Protocol (TFTP) ¾ÙÐз¢ËÍ¡£¡£¡£¡£¡£¡£Ò»µ©ÅþÁ¬µ½Ç±ÔÚ¹¥»÷ÕߵĻúе£¬£¬£¬£¬SR20 ÖÇÄÜ·ÓÉÆ÷¡°Í¨¹ý TFTP ÇëÇóÎļþÃû³Æ£¬£¬£¬£¬½«Æäµ¼Èë LUA Ú¹ÊÍÆ÷²¢½«²ÎÊýת´ï¸øËùµ¼ÈëÎļþÖÐµÄ config_test() º¯Êý¡£¡£¡£¡£¡£¡£¸ÃÚ¹ÊÍÆ÷ÒÔ root ȨÏÞÔËÐС£¡£¡£¡£¡£¡£¡±


½Ó×Å£¬£¬£¬£¬ os.execute() ÒªÁ콫ÔÊÐíδ¾­ÈÏÖ¤µÄ¹¥»÷ÕßÒÔ root ȨÏÞÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬´Ó¶øµ¼ÖÂÈκα»¹¥ÏÝµÄ TP-Link SR20 ×°±¸±»ÍêÈ«½ÓÊÜ¡£¡£¡£¡£¡£¡£


©¶´Ê¹ÓÃ


ËäÈ» tddp ÊØ»¤Àú³ÌÖ¼ÔÚ¼àÌýËùÓд«ÈëÁ÷Á¿µÄ½Ó¿Ú£¬£¬£¬£¬µ«ÅäÓÐĬÈÏ·À»ðǽµÄ SR20 ·ÓÉÆ÷½«×èÖ¹¹¥»÷Õß´Ó×°±¸ËùÔÚ¾ÖÓòÍøÒÔÍâµÄµØ·½Ê¹ÓøÃ0day¡£¡£¡£¡£¡£¡£
PoC£ºhttps://pastebin.com/GAzccR95¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚTP-Link ÉÐδ¶Ô´ËÊÂÖÃÆÀ¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/zero-day-tp-link-sr20-router-vulnerability-disclosed-by-google-dev/