GPON·ÓÉÆ÷ÑÏÖØÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-03-04

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-3917£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-3918£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-3919£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º×ÔÆÀ10£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-3920£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º×ÔÆÀ10£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-3921£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-3922£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


DASAN Networks GPON Home Gateway


Îó²î¸ÅÊö


TenableÑо¿Ô±Artem MetlaÔÚŵ»ùÑÇ£¨°¢¶û¿¨ÌØÀÊѶ£©I-240W-Q GPON·ÓÉÆ÷£¨CVE-2019-3917£¬£¬£¬£¬£¬£¬£¬CVE-2019-3918£¬£¬£¬£¬£¬£¬£¬CVE-2019-3919£¬£¬£¬£¬£¬£¬£¬CVE-2019-3920£¬£¬£¬£¬£¬£¬£¬CVE-2019-3921£¬£¬£¬£¬£¬£¬£¬CVE-2019-3922£©Öз¢Ã÷ÁËÁù¸öÎó²î ¡£¡£¡£ ÕâЩÎó²î°üÀ¨¿ÉÔ¶³Ì»á¼ûµÄºóÃÅ£¬£¬£¬£¬£¬£¬£¬Ó²±àÂëÆ¾Ö¤£¬£¬£¬£¬£¬£¬£¬ÏÂÁî×¢ÈëºÍ¿ÍÕ»»º³åÇøÒç³ö ¡£¡£¡£


Îó²îÑéÖ¤


CVE-2019-3917£ºGPON·ÓÉÆ÷±£´æÔ¶³ÌδÈÏÖ¤ÆôÓÃ/½ûÓÃTelnet ЧÀÍÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚδÈÏÖ¤µÄÇéÐÎÏÂÆôÓÃ/½ûÓÃTelnetЧÀÍ ¡£¡£¡£


curl http://[router ip]/otd


CVE-2019-3918£ºGPON·ÓÉÆ÷±£´æÓ²±àÂëÆ¾Ö¤Îó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²î»ñÈ¡µÇ¼Õ˺ÅÃÜÂë ¡£¡£¡£Ïà¹ØµÄÓ²±àÂëÕʺţº


root/admin (telnet)

root/huigu309 (telnet)

CRAFTSPERSON/ALC#FGU (telnet)

ONTUSER/SUGAR2A041 (ssh)


CVE-2019-3919¡¢CVE-2019-3920£ºGPON·ÓÉÆ÷±£´æÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§ÒâÏÂÁî ¡£¡£¡£±£´æÏÂÁî×¢ÈëµÄusb_partition²ÎÊý£º


 /GponForm/usb_restore_Form?script/ 

/GponForm/device_Form?script/ 


CVE-2019-3921£ºGPON·ÓÉÆ÷±£´æÈÏÖ¤Õ»Òç³öÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îµ¼ÖÂЧÀÍÆ÷Í߽⠡£¡£¡£


/GponForm/usb_Form?script/. 


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


CVE-2019-3922£ºGPON·ÓÉÆ÷±£´æÎ´ÈÏÖ¤Õ»Òç³öÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îµ¼ÖÂЧÀÍÆ÷Í߽⠡£¡£¡£


/GponForm/fsetup_Form


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


EXP£ºhttps://github.com/tenable/poc/blob/master/gpon/nokia_a-l_i-240w-q/gpon_poc_cve-2019-3921.py 


ÐÞ¸´½¨Òé


³§ÉÌÉÐδÌṩÎó²îÐÞ¸´¼Æ»®£¬£¬£¬£¬£¬£¬£¬Çë¹Ø×¢³§ÉÌÖ÷Ò³¸üУº http://www.dasannetworks.com 


²Î¿¼Á´½Ó


https://www.tenable.com/blog/tenable-research-discovers-remote-code-execution-vulnerabilities-in-gpon-routers

https://www.tenable.com/security/research/tra-2019-09