Verizon Fios Quantum Gateway·ÓÉÆ÷¶à¸öÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-04-10Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-3915£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.5£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-3916£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.5£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Îó²î¸ÅÊö
×îÐÂÑо¿·¢Ã÷Verizon Fios Quantum Gateway·ÓÉÆ÷±£´æ¶à¸öÎó²î¡£¡£¡£¡£¡£¡£¡£ÈôÊDZ»Ê¹Ó㬣¬£¬£¬ÕâЩÎó²î½«Ê¹¹¥»÷ÕßÍêÈ«¿ØÖÆÂ·ÓÉÆ÷²¢Éó²éÓëÆäÏà¹ØµÄËùÓÐÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£
·ÓÉÆ÷²àÃæÓÐÒ»¸öÌùÖ½¡£¡£¡£¡£¡£¡£¡£ÎªÃ¿¸ö¿Í»§Ìṩ²î±ðµÄÎÞÏßÍøÂçÃû³Æ£¬£¬£¬£¬ÎÞÏßÃÜÂëºÍÖÎÀíÔ±ÃÜÂë¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²îÖ÷ÒªÎ§ÈÆÖÎÀíÔ±ÃÜÂ룬£¬£¬£¬¶ø²»ÊÇÄúÓÃÓÚÅþÁ¬Wi-FiµÄÃÜÂë¡£¡£¡£¡£¡£¡£¡£ÖÎÀíÔ±ÃÜÂëÓÃÓÚVerizon¿Í»§µÇ¼·ÓÉÆ÷ÒÔÖ´ÐнçËµÍøÂçµÄÖÖÖÖʹÃü¡£¡£¡£¡£¡£¡£¡£Îó²î°üÀ¨£º
CVE-2019-3914 - ¾ÓÉÉí·ÝÑéÖ¤µÄÔ¶³ÌÏÂÁî×¢Èë
¿ÉÒÔͨ¹ýΪ¾ßÓÐÈ«ÐÄÉè¼ÆµÄÖ÷»úÃûµÄÍøÂ繤¾ßÌí¼Ó·À»ðǽ»á¼û¿ØÖƹæÔòÀ´´¥·¢´ËÎó²î¡£¡£¡£¡£¡£¡£¡£±ØÐè¶Ô×°±¸µÄÖÎÀíWebÓ¦ÓóÌÐò¾ÙÐÐÉí·ÝÑéÖ¤²Å»ªÖ´ÐÐÏÂÁî×¢Èë¡£¡£¡£¡£¡£¡£¡£ÔÚ´ó´ó¶¼ÇéÐÎÏ£¬£¬£¬£¬Ö»ÓоßÓÐÍâµØÍøÂç»á¼ûȨÏ޵Ĺ¥»÷Õ߲ŻªÊ¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬ÈôÊÇÆôÓÃÔ¶³ÌÖÎÀí£¬£¬£¬£¬Ôò»ùÓÚInternetµÄ¹¥»÷ÊÇ¿ÉÐе쬣¬£¬£¬ËüĬÈÏÊǽûÓõġ£¡£¡£¡£¡£¡£¡£
ÀýÈ磬£¬£¬£¬ÈôÊÇÌí¼ÓÖ÷»úÃûΪ¡°`whoami`¡±µÄÍøÂ繤¾ß£¨×¢ÖØ·´ÒýºÅ£©£¬£¬£¬£¬²¢ÇҴ˹¤¾ßÓÃÓÚ·À»ðǽ»á¼û¿ØÖƹæÔò£¬£¬£¬£¬Ôò½«Ö´ÐС®whoami¡¯ÏÂÁî¡£¡£¡£¡£¡£¡£¡£
CVE-2019-3915 - µÇÂ¼ÖØ²¥
CVE-2019-3916 - ÃÜÂëSaltй¶
Îó²îÑéÖ¤
ÏÖÔÚÒÑÓÐPoC£ºhttps://github.com/tenable/poc/blob/master/verizon/verizon_g1100_cmd_injection.py£¬£¬£¬£¬Ëü¿ÉÒÔʹÓÃÃ÷ÎÄÃÜÂë»ò×÷ΪÏÂÁîÐвÎÊýÌí¼ÓµÄ¹þÏ£Öµ¡£¡£¡£¡£¡£¡£¡£Ñ¡ÔñÈκÎÒªÁì¶¼»áµ¼ÖÂÀֳɵǼ·ÓÉÆ÷µÄWeb½çÃæ¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÃÀÖ³ÉÈçÏÂͼ£º
ÐÞ¸´½¨Òé
VerizonÐû²¼Á˹̼þ°æ±¾02.02.00.13À´ÐÞ¸´ÕâЩÎó²î¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.tenable.com/blog/verizon-fios-quantum-gateway-routers-patched-for-multiple-vulnerabilities
https://www.bleepingcomputer.com/news/security/verizon-fixes-bugs-allowing-full-control-of-fios-quantum-router/