D-Link DAP-1860 Çå¾²Îó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2019-12-10Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-19597£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-19598£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Model |
Revision |
Affected FW |
Fixed FW |
DAP-1860 |
All Ax revisions |
v1.04b01 and below (older) |
v1.04b03 Beta Hot Fix |
Îó²î¸ÅÊö
D-Link DAP-1860ÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îWiFi¹æÄ£À©Õ¹Æ÷¡£¡£¡£¡£¡£
CVE-2019-19597
¹¥»÷Õ߿ɽèÖúHNAP_AUTH HTTPÍ·ÖеÄshellÔª×Ö·ûʹÓøÃÎó²îÒÔrootȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
CVE-2019-19598
¹¥»÷Õ߿ɽèÖúHNAP_AUTHÍ·ÖеÄʱ¼ä´ÁֵʹÓøÃÎó²îδ¾Éí·ÝÑéÖ¤±ã¿É»á¼ûÖÎÀíÔ±¹¦Ð§¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10135
²Î¿¼Á´½Ó
https://chung96vn.wordpress.com/2019/11/15/d-link-dap-1860-vulnerabilities/