¡¾Îó²îͨ¸æ¡¿D-Link VPN·ÓÉÆ÷¶à¸öÏÂÁî×¢ÈëÎó²î

Ðû²¼Ê±¼ä 2020-12-10

0x00 Îó²î¸ÅÊö

²úÆ·Ãû³Æ

CVE ID

Àà ÐÍ

Îó²îÆ·¼¶

Ô¶³ÌʹÓÃ

D-Link VPN·ÓÉÆ÷

CVE-2020-25757

ÏÂÁî×¢Èë

¸ßΣ

ÊÇ

CVE-2020-25758

crontab×¢Èë

¸ßΣ

ÊÇ

CVE-2020-25759

ÏÂÁî×¢Èë

¸ßΣ

ÊÇ

 

0x01 Îó²îÏêÇé

 

image.png

2020Äê12ÔÂ09ÈÕ£¬£¬£¬£¬ £¬£¬D-Link VPN·ÓÉÆ÷±»Åû¶¶à¸ö0 dayÎó²î£¨CVE-2020-25757¡¢CVE-2020-25758¡¢CVE-2020-25759£©¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔ»á¼û¡° Unified Services Router¡± Web½çÃæµÄ¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÌᳫ¶ñÒâÇëÇóÀ´×¢ÈëÏÂÁ£¬£¬£¬ £¬£¬»òÌí¼ÓCronʹÃüÀ´Ö´ÐÐí§ÒâÏÂÁ£¬£¬£¬ £¬£¬ÕâЩ¶ñÒâÏÂÁÒÔrootȨÏÞÖ´ÐУ¬£¬£¬£¬ £¬£¬×îÖÕ¿ÉÒÔ¿ØÖÆÕû¸ö×°±¸¡£¡£¡£¡£¡£¡£¡£Îó²îϸ½ÚÈçÏ£º

D-Link VPN·ÓÉÆ÷δ¾­Éí·ÝÑéÖ¤µÄÏÂÁî×¢ÈëÎó²î£¨CVE-2020-25757£©

lua-cgi²Ù×÷ÎÞÐèÉí·ÝÑéÖ¤¼´¿É»á¼û£¬£¬£¬£¬ £¬£¬ÆäÖ´ÐÐlua¿âº¯Êýʱ£¬£¬£¬£¬ £¬£¬¸Ãº¯Êý½«Óû§ÌṩµÄÊý¾Ýת´ï¸ø¶Ôos.popen£¨£©µÄŲÓ㬣¬£¬£¬ £¬£¬×÷ΪÅÌËã¹þÏ£µÄÏÂÁîµÄÒ»²¿·Ö£º/platform.cgi?action=duaAuth£¬£¬£¬£¬ £¬£¬/platform.cgi?action=duaLogout¡£¡£¡£¡£¡£¡£¡£

D-Link VPN·ÓÉÆ÷¾­ÓÉÈÏÖ¤µÄCrontab×¢ÈëÎó²î£¨CVE-2020-25758£©

ÓÉÓÚÔÚÉÏ´«Ê±¿ÉÒÔÇáËÉÈÆ¹ý¶ÔÉèÖÃÎļþ¾ÙÐÐÉí·ÝÑéÖ¤µÄ»úÖÆ£¬£¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î½¨Éè¶ñÒâÉèÖÃÎļþ£¬£¬£¬£¬ £¬£¬²¢Ìí¼ÓеÄcron£¨ÍýÏëʹÃü£©ÌõÄ¿£¬£¬£¬£¬ £¬£¬²¢ÒÔrootÉí·ÝÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£

D-Link VPN·ÓÉÆ÷¾­ÓÉÈÏÖ¤µÄÏÂÁî×¢ÈëÎó²î£¨CVE-2020-25759£©

Lua-CGI´¦Öóͷ£À´×Ô¡°Unified Services Router¡±web½çÃæÖС°Package Management¡±±íµ¥µÄÇëÇóʱ£¬£¬£¬£¬ £¬£¬¶Ôת´ï¸øOSµÄ¶à¸ö´øPOST²ÎÊýµÄPayloadûÓÐÔÚЧÀÍÆ÷¶Ë¹ýÂË¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓÃexecute£¨£©º¯Êý½«ÉÏ´«µÄÎļþÒÆ¶¯µ½ÁíÒ»¸öĿ¼¡£¡£¡£¡£¡£¡£¡£

 

×èÖ¹ÏÖÔÚ£¬£¬£¬£¬ £¬£¬Í¨¹ýzoomeyeËÑË÷·¢Ã÷£¬£¬£¬£¬ £¬£¬ÖйúÓÐ5637402¸öD-Link VPN×°±¸¡£¡£¡£¡£¡£¡£¡£

image.png

 

Ó°Ïì¹æÄ££º

ÔËÐй̼þv3.17¼°Ö®Ç°°æ±¾µÄ£ºDSR-150¡¢DSR-250¡¢DSR-500¡¢DSR-1000AC

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚD-LinkÕýÔÚ¿ª·¢Ïà¹Ø²¹¶¡³ÌÐò£¬£¬£¬£¬ £¬£¬¹Ù·½¹Ì¼þ°æ±¾Ô¤¼ÆÔÚ12ÔÂÖÐÑ®Ðû²¼¡£¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10195

 

0x03 ²Î¿¼Á´½Ó

https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10195

https://www.digitaldefense.com/resources/vulnerability-research/d-link-vpn-router/

https://threatpost.com/d-link-routers-zero-day-flaws/162064/

 

0x04 ʱ¼äÏß

2020-12-09  Digital DefenseÅû¶Îó²î

2020-12-10  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png