NETGEARÎÞÏß·ÓÉÆ÷DoS·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-09-11¡ñ·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-5054£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-5055£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
¡ñÓ°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
NETGEAR N300 WNR2000v5 Firmware Version V1.0.0.70
¡ñ·ì϶¸ÅÊö
˼¿ÆTalos·¢ÏÖNETGEAR N300ϵÁÐÎÞÏß·ÓÉÆ÷Ô̺¬Á½¸ö»Ø¾ø·þÎñ·ì϶¡£¡£¡£¡£¡£¡£¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýÏò·ÓÉÆ÷µÄ·ÖÆçÖ°ÄÜ·¢ËͶñÒâSOAPºÍHTTPÒªÇóÀ´ÀûÓÃÕâЩ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÆäÆëÈ«±ÀÀ£¡£¡£¡£¡£¡£¡£¡£
µÚÒ»¸ö·ì϶ÊÇCVE-2019-5054£¬£¬£¬£¬£¬£¬£¬£¬´æÔÚÓÚHTTP·þÎñÆ÷µÄ»á»°´¦ÖÃÖ°ÄÜÖУ¬£¬£¬£¬£¬£¬£¬£¬·¢Ë͵½Éí·ÝÑéÖ¤Ò³ÃæµÄ¿ÕUser-Agent×Ö·û´®HTTPÒªÇó¿ÉÄܵ¼Ö¿ÕÖ¸Õë½âÒýÓ㬣¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂHTTP·þÎñ±ÀÀ£¡£¡£¡£¡£¡£¡£¡£
µÚ¶þ¸ö·ì϶ÊÇCVE-2019-5055£¬£¬£¬£¬£¬£¬£¬£¬´æÔÚÓÚÖ÷»ú½Ó¼ûµãÊØ»¤·¨Ê½£¨hostapd£©ÖУ¬£¬£¬£¬£¬£¬£¬£¬·¢Ë͵½<WFAWLANConfig£º1££PutMessage>·þÎñµÄÎÞЧÐòÁÐSOAPÒªÇó¿ÉÄܵ¼Ö¿ÕÖ¸Õë½âÒýÓ㬣¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂhostapd·þÎñ±ÀÀ£¡£¡£¡£¡£¡£¡£¡£
¡ñ·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£
¡ñ½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://kb.netgear.com/000061228/WNR2000v5-Firmware-Version-1-0-0-72¡£¡£¡£¡£¡£¡£¡£
¡ñ²Î¿¼Á´½Ó
https://blog.talosintelligence.com/2019/09/vuln-spotlight-Netgear-N300-routers-DoS-sept-2019.html


¾©¹«Íø°²±¸11010802024551ºÅ