CVE-2020-12695 | UPnPÐÒéCallStrangerÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-06-090x00 Îó²î¸ÅÊö
CVE ID |
CVE-2020-12695 |
ʱ ¼ä |
2020-06-09 |
Àà ÐÍ |
|
µÈ ¼¶ |
ÑÏÖØ |
Ô¶³ÌʹÓà |
ÊÇ |
Ó°Ïì¹æÄ£ |
|
0x01 Îó²îÏêÇé
ͨÓü´²å¼´Óã¨Universal Plug and Play£¬£¬£¬£¬£¬¼ò³ÆUPnP£©ÊÇÓÉ¿ª·ÅÅþÁ¬»ù½ð»á£¨OCF£©ÖÎÀíµÄÒ»Ì×ÍøÂçÐÒé¡£¡£¡£¸ÃÐÒéµÄÄ¿µÄÊÇʹ¼ÒÍ¥ÍøÂ磨Êý¾Ý¹²Ïí¡¢Í¨Ñ¶ºÍÓéÀÖ£©ºÍ¹«Ë¾ÍøÂçÖеÄÖÖÖÖ×°±¸Äܹ»Ï໥ÎÞ·ìÅþÁ¬£¬£¬£¬£¬£¬²¢¼ò»¯Ïà¹ØÍøÂçµÄʵÏÖ¡£¡£¡£UPnPͨ¹ý½ç˵ºÍÐû²¼»ùÓÚ¿ª·Å¡¢ÒòÌØÍøÍ¨Ñ¶ÍøÐÒé±ê×¼µÄUPnP×°±¸¿ØÖÆÐÒéÀ´ÊµÏÖÕâһĿµÄ¡£¡£¡£
2019Äê12Ô£¬£¬£¬£¬£¬Ò»Î»Ãû½ÐYunus?adirciµÄÇå¾²¹¤³ÌʦÔÚÕâÏΪÆÕ¼°µÄÊÖÒÕÖз¢Ã÷ÁËÒ»¸öÎó²î£¨CVE-2020-12695£©£¬£¬£¬£¬£¬ÃüÃûΪCallStranger¡£¡£¡£ÔÚÊýÊ®ÒÚ¸öUPNP×°±¸Öз¢Ã÷µÄCallStrangerÎó²î¿Éµ¼ÖÂÊý¾Ýй¶£¨×ÝÈ»ÄúÓÐDLP/½çÏßÇå¾²×°±¸£©»òɨÃèÄúµÄÍøÂ磬£¬£¬£¬£¬ÉõÖÁµ¼ÖÂÄúµÄÍøÂç¼ÓÈëDDoS¹¥»÷¡£¡£¡£¸ÃÎó²îÓÉUPnP SUBSCRIBEº¯ÊýÖеıêÍ·Öµ»Øµ÷ÒýÆð£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒԽṹһ¸öº¬ÖøÃûÌùýʧµÄ±êÍ·Öµ»Øµ÷µÄTCPÊý¾Ý°ü·¢Ë͵½Ô¶¶Ë×°±¸£¬£¬£¬£¬£¬À´Ê¹Óû¥ÁªÍøÉÏÖ§³ÖUPnPÐÒéµÄÖÇÄÜ×°±¸£¬£¬£¬£¬£¬ÀýÈçÉãÏñ»ú£¬£¬£¬£¬£¬DVR£¬£¬£¬£¬£¬´òÓ¡»ú£¬£¬£¬£¬£¬Â·ÓÉÆ÷µÈ¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î¾ÙÐÐÒÔϲÙ×÷£º
? ÈÆ¹ýDLPºÍÍøÂçÇå¾²×°±¸¿ÉÇÔÈ¡Êý¾Ý£»£»£»£»£»£»
? ʹÓÃÊý°ÙÍò¸öÃæÏòInternetµÄUPnP×°±¸×÷Ϊ·Å´óµÄ·´ÉäTCP DDoS/SYN FloodÔ´£»£»£»£»£»£»
? ´ÓÃæÏòInternetµÄUPnP×°±¸É¨ÃèÄÚ²¿¶Ë¿Ú¡£¡£¡£
¸ÃÎó²îÓ°Ïì¹æÄ£´ó£¬£¬£¬£¬£¬Ê¹ÓÃshodanɨÃè·¢Ã÷ԼĪÓÐ545Íǫ̀¿ªÆôUPnP¹¦Ð§µÄ×°±¸ÅþÁ¬µ½»¥ÁªÍø£¬£¬£¬£¬£¬ÕâЩװ±¸ÈÝÒ׳ÉΪÎïÁªÍø½©Ê¬ÍøÂçºÍAPT×éÖ¯µÄ¹¥»÷Ä¿µÄ¡£¡£¡£
?adirciÌåÏÖ£¬£¬£¬£¬£¬ËûÈ¥ÄêÔøÍ¨ÖªOCF£¬£¬£¬£¬£¬¸Ã×éÖ¯ÒÑÓÚ2020Äê4ÔÂ17ÈÕ¸üÐÂÁËUPnPÐÒ鹿·¶¡£¡£¡£ÓÉÓÚÕâÊÇÒ»¸öÐÒéÎó²î£¬£¬£¬£¬£¬¹©Ó¦ÉÌ¿ÉÄÜÐèÒªºÜ³¤Ê±¼ä²Å»ªÌṩ²¹¶¡³ÌÐò¡£¡£¡£
ÏÖÔÚÒѾȷÈϵÄÊÜÓ°ÏìµÄÁбíÈçÏ£º
Xbox One- OS Version 10.0.19041.2494
ADB TNR-5720SX Box (TNR-5720SX/v16.4-rc-371-gf5e2289 UPnP/1.0 BH-upnpdev/2.0)
Asus ASUS Media Streamer
Asus Rt-N11
Belkin WeMo
Broadcom ADSL Modems
Canon Canon SELPHY CP1200 Printer
Cisco X1000 - (LINUX/2.4 UPnP/1.0 BRCM400/1.0)
Cisco X3500 - (LINUX/2.4 UPnP/1.0 BRCM400/1.0)
D-Link DVG-N5412SP WPS Router (OS 1.0 UPnP/1.0 Realtek/V1.3)
EPSON EP, EW, XP Series (EPSON_Linux UPnP/1.0 Epson UPnP SDK/1.0)
HP Deskjet, Photosmart, Officejet ENVY Series (POSIX, UPnP/1.0, Intel MicroStack/1.0.1347)
Huawei HG255s Router - Firmware HG255sC163B03 (ATP UPnP Core)
NEC AccessTechnica WR8165N Router ( OS 1.0 UPnP/1.0 Realtek/V1.3)
Philips 2k14MTK TV - Firmware TPL161E_012.003.039.001
Samsung UE55MU7000 TV - Firmware T-KTMDEUC-1280.5, BT - S
Samsung MU8000 TV
Siemens CNE1000 Camera
Sony Media Go Media application
Stream What You Hear Stream What You Hear
Toshiba TCC-C1 Media Device
TP-Link Archer C50
Trendnet TV-IP551W
Ubiquiti UniFi Controller
ZTE ZXV10 W300
ZTE H108N
Zyxel AMG1202-T10B
0x02 ´¦Öóͷ£½¨Òé
1. ÈôÊÇûÓÐÓªÒµ/ÊÖÒÕµÄÐèÇ󣬣¬£¬£¬£¬½¨Ò鹨±Õµ½InternetµÄUPnP¶Ë¿Ú£»£»£»£»£»£»
2. ½¨Òé×è¶ÏSUBSCRIBEºÍNOTIFY HTTPÊý¾Ý°ü£»£»£»£»£»£»
3. ¼ì²éÈÕÖ¾£¬£¬£¬£¬£¬È·ÈÏÊÇ·ñÓÐÈËʹÓôËÎó²î¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÒѾÐû²¼ÁËPoC£¬£¬£¬£¬£¬Óû§¿ÉÒÔÓÃÀ´È·¶¨ÆäÖÇÄÜ×°±¸ÊÇ·ñÈÝÒ×Êܵ½CallStrangerÎó²îµÄ¹¥»÷¡£¡£¡£
https://github.com/yunuscadirci/CallStranger
0x03 Ïà¹ØÐÂÎÅ
https://www.zdnet.com/article/callstranger-vulnerability-lets-attacks-bypass-security-systems-and-scan-lans/#ftag=RSSbaffb68
0x04 ²Î¿¼Á´½Ó
https://callstranger.com/
https://github.com/yunuscadirci/CallStranger
https://kb.cert.org/vuls/id/339275
0x05 ʱ¼äÏß
2020-06-08 Îó²î¹ûÕæ
2020-06-09 VSRCÐû²¼Îó²îͨ¸æ
