D-Link DAP-1860 Çå¾²Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2019-12-10

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-19597£¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-19598£¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Model

Revision

Affected FW

Fixed FW

DAP-1860

All Ax revisions

v1.04b01 and below (older)

v1.04b03 Beta Hot Fix

Îó²î¸ÅÊö


D-Link DAP-1860ÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îWiFi¹æÄ£À©Õ¹Æ÷¡£¡£¡£¡£¡£


CVE-2019-19597

¹¥»÷Õ߿ɽèÖúHNAP_AUTH HTTPÍ·ÖеÄshellÔª×Ö·ûʹÓøÃÎó²îÒÔrootȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£


CVE-2019-19598

¹¥»÷Õ߿ɽèÖúHNAP_AUTHÍ·ÖеÄʱ¼ä´ÁֵʹÓøÃÎó²îδ¾­Éí·ÝÑéÖ¤±ã¿É»á¼ûÖÎÀíÔ±¹¦Ð§¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬ £¬²¹¶¡»ñÈ¡Á´½Ó£º

https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10135


²Î¿¼Á´½Ó


https://chung96vn.wordpress.com/2019/11/15/d-link-dap-1860-vulnerabilities/