TP-Link SR20 ·ÓÉÆ÷ 0day·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-03-29·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾£º
TP-Link SR20 ÖÇÄܼÒͥ·ÓÉÆ÷
·ì϶¸ÅÊö
Òò·ì϶»ã±¨Ìá½»ºó90ÌìÄÚÈÔδÊÕµ½ÈκλØÓ¦£¬£¬£¬£¬£¬£¬¹È¸è°²È«¿ª·¢Ô±Ñ¡Ôñ¹«¿ª TP-Link SR20 ÖÇÄܼÒͥ·ÓÉÆ÷ÖеÄÒ»¸ö 0day ËÁÒâ´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿Éµ¼ÖÂλÓÚÍ³Ò»ÍøÂçµÄDZÔÚ¹¥»÷ÕßÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£¡£
TP-Link ·ÓÉÆ÷ʱʱÒÔ root ȨÏÞÔËÐÐÃûΪ¡°tddp£¨TP-Link É豸µ÷ÊÔºÍ̸£©¡±µÄ¹ý³Ì£¬£¬£¬£¬£¬£¬¶øÕâ¸ö¹ý³Ì´Ëǰ±»Ö¸Ô̺¬ÆäËü¶à¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£¡£
TDDP ÔÊÐíÔÚÉ豸ÉÏÔËÐÐÁ½ÖÖÀàÐ͵ĺÅÁµÚÒ»ÖÖ²»ÒªÇóÈÏÖ¤£¬£¬£¬£¬£¬£¬¶øµÚ¶þÖÖÒªÇóÖÎÀíԱƾ֤¡£¡£¡£¡£¡£¡£¡£¡£
Ò×Êܹ¥»÷µÄ·ÓÉÆ÷¶³öÁ˶à¸öµÚÒ»ÖÖÀàÐ͵ĺÅÁ¼´²»ÒªÇóÈÏÖ¤µÄºÅÁ£¬£¬£¬£¬£¬£¬ÆäÖÐÒ»ÖÖºÅÁî 0X1f¡¢ÒªÇó 0X01¡°ËƺõÊÇΪijÖÖÅäÖÃÑéÖ¤ÉèÖá±£¬£¬£¬£¬£¬£¬ÔÊÐí×¼ºÚ¿Í·¢ËÍÒ»¸öºÅÁ£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Ò»¸öÎļþÃû³Æ¡¢Ò»¸ö·ÖºÅÒÔ¼°²ÎÊýÀ´³õʼ»¯ÀûÓùý³Ì¡£¡£¡£¡£¡£¡£¡£¡£
ÕâÑùÖ¸Áî TP-Link ·ÓÉÆ÷½«ÌØÊâ»ú¹ØµÄÒªÇóͨ¹ý Trivial File Transfer Protocol (TFTP) ½øÐз¢ËÍ¡£¡£¡£¡£¡£¡£¡£¡£Ò»µ©Ïνӵ½Ç±ÔÚ¹¥»÷ÕߵĻúе£¬£¬£¬£¬£¬£¬SR20 ÖÇÄÜ·ÓÉÆ÷¡°Í¨¹ý TFTP ÒªÇóÎļþÃû³Æ£¬£¬£¬£¬£¬£¬½«Æäµ¼Èë LUA Ú¹ÊÍÆ÷²¢½«²ÎÊý´«µÝ¸øËùµ¼ÈëÎļþÖÐµÄ config_test() º¯Êý¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÚ¹ÊÍÆ÷ÒÔ root ȨÏÞÔËÐС£¡£¡£¡£¡£¡£¡£¡£¡±
½Ó×Å£¬£¬£¬£¬£¬£¬ os.execute() ²½Ö轫ÔÊÐíδ¾ÈÏÖ¤µÄ¹¥»÷ÕßÒÔ root ȨÏÞÖ´ÐÐËÁÒâºÅÁ£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÈκα»¹¥Ï嵀 TP-Link SR20 É豸±»ÆëÈ«ÊÕÊÜ¡£¡£¡£¡£¡£¡£¡£¡£
©¶´ÀûÓÃ
¹ÌÈ» tddp ÊØ»¤¹ý³ÌÖ¼ÔÚ¼àÌýËùÓд«ÈëÁ÷Á¿µÄ½Ó¿Ú£¬£¬£¬£¬£¬£¬µ«ÅäÓÐĬÈÏ·À»ðǽµÄ SR20 ·ÓÉÆ÷½«×èÖ¹¹¥»÷Õß´ÓÉ豸µØµã¾ÖÓòÍøÒÔ±íµÄ´¦ËùÀûÓøÃ0day¡£¡£¡£¡£¡£¡£¡£¡£
PoC£ºhttps://pastebin.com/GAzccR95¡£¡£¡£¡£¡£¡£¡£¡£
½¨¸´½¨Òé
ĿǰTP-Link ÉÐδ¶Ô´ËÊÂÖÃÆÀ¡£¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/zero-day-tp-link-sr20-router-vulnerability-disclosed-by-google-dev/


¾©¹«Íø°²±¸11010802024551ºÅ