ZyXEL Cloud CNM SecuManagerδÊÚȨԶ³Ì´úÂëÖ´ÐÐÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-03-16Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ZyXEL Cloud CNM SecuManager <=3.1.1
Îó²î¸ÅÊö
Zyxel Cloud CNM SecuManagerÊÇÒ»¿îÖÜÈ«µÄÍøÂçÖÎÀíÈí¼þ£¬£¬£¬¿ÉÌṩ¼¯³É¿ØÖÆÌ¨À´¼àÊÓºÍÖÎÀíÇå¾²Íø¹Ø£¬£¬£¬°üÀ¨ZyWALLUSGºÍVPNϵÁС£¡£¡£¡£
Zyxel Cloud CNM SecuManager±£´æÎ´ÊÚȨԶ³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÒÔͨ¹ýÀÄÓ÷¾¶Îª /live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids=µÄ APIŲÓõִïÔ¶³Ì´úÂëÖ´ÐеÄÄ¿µÄ¡£¡£¡£¡£
ר¼ÒÃÇ·¢Ã÷Á˰üÀ¨´ËÎó²îÔÚÄڵĹ²16¸öÎó²î£¬£¬£¬°üÀ¨ÓÃÓÚ²»Çå¾²ÄÚ´æ´æ´¢µÄĬÈÏÆ¾Ö¤ºÍºóÃÅ¡£¡£¡£¡£×¨¼Ò·¢Ã÷µÄÎÊÌâµÄÍêÕûÁбíÈçÏ£º
1. Ó²±àÂëµÄSSHЧÀÍÆ÷ÃÜÔ¿
2. MySQLÖеĺóÃÅÕÊ»§
3. EjabberdÖеÄÓ²±àÂëÖ¤ÊéºÍºóÃÅ»á¼û
4. ÎÞÐèÉí·ÝÑéÖ¤¼´¿É·¿ªZODB´æ´¢
5. MyZyxel¡°ÔÆ¡±Ó²±àÂëµÄÉñÃØ
6. Ó²±àÂëµÄÉñÃØ£¬£¬£¬API
7. ÖÎÀíÔ±ÕÊ»§µÄÔ¤½ç˵ÃÜÂë
8. ¶Ô¡°ÔÆ¡±µÄ²»Çå¾²ÖÎÀí
9. xmppCnrSender.pyÈÕ־תÒåÐòÁÐ×¢Èë
10. xmppCnrSender.pyûÓÐÉí·ÝÑéÖ¤ºÍÃ÷ÎÄͨѶ
11. ¹ýʧµÄHTTPÇëÇóµ¼ÖÂZopeÁè¼Ý¹æÄ£»á¼û
12. Web½çÃæÉϵÄXSS
13. ˽ÈËSSHÃÜÔ¿
14. ºóÃÅAPI
15. ºóÃÅÖÎÆÊÎö¼ûºÍRCE
16. ¾ßÓÐchroot»á¼ûȨÏÞµÄÔ¤ÈÏÖ¤RCE
¾Ýͳ¼Æ£¬£¬£¬Zyxel Cloud CNM SecuManagerÔÚÖйú̻¶ÔÚÍøÉϵÄÊýÄ¿ºÍÂþÑÜÈçÏÂͼ£º
Îó²îÑéÖ¤
PoC£ºhttps://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÉÐδÌṩÏà¹ØÎó²î²¹¶¡Á´½Ó£¬£¬£¬Çë¹Ø×¢³§ÉÌÖ÷Ò³ËæÊ±¸üУºhttps://www.zyxel.cn/¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.cnvd.org.cn/flaw/show/CNVD-2020-16839