Cisco Small Business RV320ºÍRV325Îó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-01-28Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-1652£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.2£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1653£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì¹æÄ£
ÊÜÓ°Ïì²úÆ·£º
CVE-2019-1652
ʹÓÃ1.4.2.15°æ±¾ÖÁ1.4.2.19°æ±¾¹Ì¼þµÄCisco Small Business RV320ºÍRV325
CVE-2019-1653
ʹÓÃ1.4.2.15°æ±¾ÖÁ1.4.2.17°æ±¾¹Ì¼þµÄCisco Small Business RV320ºÍRV325
Îó²î¸ÅÊö
Cisco Small Business RV320ºÍRV325¶¼ÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÆóÒµ¼¶Â·ÓÉÆ÷¡£¡£¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬£¬£¬Ë¼¿ÆÎªÂ·ÓÉÆ÷ÐͺŠRV320 ºÍ RV325 Ðû²¼¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÒ»¸öÏÂÁî×¢ÈëÎó²î (CVE-2019-1652) ºÍÒ»¸öÐÅÏ¢×ß©Îó²î (CVE-2019-1653)£¬£¬£¬£¬£¬£¬ÕâÁ½¸öÎó²î¾ùλÓÚ·ÓÉÆ÷µÄ web ÖÎÀí½Ó¿ÚÖС£¡£¡£¡£¡£¡£±»ÆØÎó²îÇÒ POCºÍEXP ÒÑÐû²¼£¬£¬£¬£¬£¬£¬µ¼Ö¹¥»÷ÕßÄܹ»É¨ÃèÒ×Êܹ¥»÷µÄ×°±¸²¢ÍêÈ«¿ØÖÆËüÃÇ¡£¡£¡£¡£¡£¡£¸ÅÊöÈçÏ£º
CVE-2019-1652
»ùÓÚWebµÄÖÎÀí½çÃæ±£´æÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓÐ׼ȷµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÖÆµÄHTTP POSTÇëÇóʹÓøÃÎó²îÒÔrootȨÏÞÔڵײãLinux shellÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
CVE-2019-1653
»ùÓÚWebµÄÖÎÀí½çÃæ±£´æÐÅϢй¶Îó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐò¶ÔURLsÖ´ÐÐÁ˹ýʧµÄ»á¼û¿ØÖÆ¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýHTTP»òHTTPSÐÒéÅþÁ¬ÊÜÓ°ÏìµÄ×°±¸²¢ÇëÇóURLsʹÓøÃÎó²î¼ìË÷Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£
Îó²îʹÓÃ
ÏÖÔÚ£¬£¬£¬£¬£¬£¬Îó²îµÄPOCºÍEXPÒѹûÕæ£º
CVE-2019-1652
POC: https://cxsecurity.com/issue/WLB-2019010236
EXP: https://github.com/0x27/CiscoRV320Dump
CVE-2019-1653
POC: https://cxsecurity.com/issue/WLB-2019010235
EXP: https://github.com/0x27/CiscoRV320Dump
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£º
CVE-2019-1652
Çë¸üÐÂÖÁ1.4.2.20°æ±¾¡£¡£¡£¡£¡£¡£
CVE-2019-1653
Çë¸üÐÂÖÁ1.4.2.19°æ±¾¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://cxsecurity.com/issue/WLB-2019010236
https://cxsecurity.com/issue/WLB-2019010235
https://github.com/0x27/CiscoRV320Dump
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-info
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-inject