ZyXEL Cloud CNM SecuManagerδÊÚȨԶ³Ì´úÂëÖ´ÐÐÎó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-03-16

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ £¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ZyXEL Cloud CNM SecuManager <=3.1.1


Îó²î¸ÅÊö


Zyxel Cloud CNM SecuManagerÊÇÒ»¿îÖÜÈ«µÄÍøÂçÖÎÀíÈí¼þ £¬£¬ £¬¿ÉÌṩ¼¯³É¿ØÖÆÌ¨À´¼àÊÓºÍÖÎÀíÇå¾²Íø¹Ø £¬£¬ £¬°üÀ¨ZyWALLUSGºÍVPNϵÁС£¡£¡£¡£


Zyxel Cloud CNM SecuManager±£´æÎ´ÊÚȨԶ³Ì´úÂëÖ´ÐÐÎó²î £¬£¬ £¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÒÔͨ¹ýÀÄÓ÷¾¶Îª /live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids=µÄ APIŲÓõִïÔ¶³Ì´úÂëÖ´ÐеÄÄ¿µÄ¡£¡£¡£¡£


ר¼ÒÃÇ·¢Ã÷Á˰üÀ¨´ËÎó²îÔÚÄڵĹ²16¸öÎó²î £¬£¬ £¬°üÀ¨ÓÃÓÚ²»Çå¾²ÄÚ´æ´æ´¢µÄĬÈÏÆ¾Ö¤ºÍºóÃÅ¡£¡£¡£¡£×¨¼Ò·¢Ã÷µÄÎÊÌâµÄÍêÕûÁбíÈçÏ£º


1. Ó²±àÂëµÄSSHЧÀÍÆ÷ÃÜÔ¿

2. MySQLÖеĺóÃÅÕÊ»§

3. EjabberdÖеÄÓ²±àÂëÖ¤ÊéºÍºóÃÅ»á¼û

4. ÎÞÐèÉí·ÝÑéÖ¤¼´¿É·­¿ªZODB´æ´¢

5. MyZyxel¡°ÔÆ¡±Ó²±àÂëµÄÉñÃØ

6. Ó²±àÂëµÄÉñÃØ £¬£¬ £¬API

7. ÖÎÀíÔ±ÕÊ»§µÄÔ¤½ç˵ÃÜÂë

8. ¶Ô¡°ÔÆ¡±µÄ²»Çå¾²ÖÎÀí

9. xmppCnrSender.pyÈÕ־תÒåÐòÁÐ×¢Èë

10. xmppCnrSender.pyûÓÐÉí·ÝÑéÖ¤ºÍÃ÷ÎÄͨѶ

11. ¹ýʧµÄHTTPÇëÇóµ¼ÖÂZopeÁè¼Ý¹æÄ£»á¼û

12. Web½çÃæÉϵÄXSS

13. ˽ÈËSSHÃÜÔ¿

14. ºóÃÅAPI

15. ºóÃÅÖÎÆÊÎö¼ûºÍRCE

16. ¾ßÓÐchroot»á¼ûȨÏÞµÄÔ¤ÈÏÖ¤RCE


¾Ýͳ¼Æ £¬£¬ £¬Zyxel Cloud CNM SecuManagerÔÚÖйú̻¶ÔÚÍøÉϵÄÊýÄ¿ºÍÂþÑÜÈçÏÂͼ£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Îó²îÑéÖ¤


PoC£ºhttps://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÉÐδÌṩÏà¹ØÎó²î²¹¶¡Á´½Ó £¬£¬ £¬Çë¹Ø×¢³§ÉÌÖ÷Ò³ËæÊ±¸üУºhttps://www.zyxel.cn/¡£¡£¡£¡£


²Î¿¼Á´½Ó



https://www.cnvd.org.cn/flaw/show/CNVD-2020-16839