¡¾Îó²îͨ¸æ¡¿CVE-2020-29583 ZyxelÓ²±àÂëÆ¾Ö¤Îó²î

Ðû²¼Ê±¼ä 2021-01-04

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2020-29583

ʱ   ¼ä

2021-01-04

Àà   ÐÍ


µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


 

0x01 Îó²îÏêÇé

image.png

Zyxel£¨ºÏÇڿƼ¼£©Êǹú¼Ê×ÅÃûµÄÍøÂç¿í´øÏµÍ³¼°½â¾ö¼Æ»®µÄ¹©Ó¦ÉÌ¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬È«ÇòÓÐÁè¼Ý100000̨Zyxel·À»ðǽ¡¢VPNÍø¹ØºÍ»á¼ûµã¿ØÖÆÆ÷¡£¡£¡£¡£¡£¡£

2020Äê12ÔÂ23ÈÕ£¬£¬£¬£¬ZyxelÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬Æä·À»ðǽºÍAP¿ØÖÆÆ÷Öб£´æÒ»¸öÇå¾²Îó²î£¨CVE-2020-29583£©£¬£¬£¬£¬ÆäCVSSÆÀ·Ö7.8¡£¡£¡£¡£¡£¡£

Zyxel·À»ðǽºÍAP¿ØÖÆÆ÷ÖаüÀ¨Ò»¸ö¡° zyfwp¡±ÕÊ»§£¬£¬£¬£¬¸ÃÕÊ»§¿Éͨ¹ýFTP×Ô¶¯¸üй̼þ¡£¡£¡£¡£¡£¡£ÓÉÓÚ¸ÃÕË»§µÄÃÜÂë²»¿É¸ü¸Ä£¬£¬£¬£¬²¢ÇÒ¿ÉÒÔÔڹ̼þÖÐÒÔÃ÷ÎÄÐÎʽ£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÕÊ»§ÒÔÖÎÀíԱȨÏ޵Ǽ¡£¡£¡£¡£¡£¡£

$ ssh zyfwp@192.168.1.252

Password: Pr*******Xp

Router> show users current

No: 1

  Name: zyfwp

  Type: admin

(...)

Router>

 

Ó°Ïì¹æÄ££º

¸ß¼¶Íþв·À»¤£¨ATP£©ÏµÁУ¨Ö÷ÒªÓÃ×÷·À»ðǽ£©

ͳһÇå¾²Íø¹Ø£¨USG£©ÏµÁУ¨ÓÃ×÷»ìÏý·À»ðǽºÍVPNÍø¹Ø£©

USG FLEXϵÁУ¨ÓÃ×÷»ìÏý·À»ðǽºÍVPNÍø¹Ø£©

VPNϵÁУ¨ÓÃ×÷VPNÍø¹Ø£©

NXCϵÁУ¨ÓÃ×÷WLAN½ÓÈëµã¿ØÖÆÆ÷£©

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ£¬£¬£¬£¬ZyxelÒѾ­Ðû²¼ÁË´ËÎó²îµÄ²¿·ÖÇå¾²¸üУ¬£¬£¬£¬NXCϵÁеIJ¹¶¡Ô¤¼Æ½«ÓÚ2021Äê4ÔÂÐû²¼£¬£¬£¬£¬½¨Òé²Î¿¼Ï±í¸üÐÂÖÁ×îа汾£º

ÊÜÓ°Ïì²úÆ·

²¹¶¡

·À»ðǽ

ATPϵÁÐÕýÔÚÔËÐй̼þZLD V4.60

2020Äê12ÔµÄZLD V4.60²¹¶¡1

USGϵÁÐÔËÐй̼þZLD V4.60

2020Äê12ÔµÄZLD V4.60²¹¶¡1

USG FLEXϵÁÐÔËÐй̼þZLD V4.60

2020Äê12ÔµÄZLD V4.60²¹¶¡1

ÔËÐй̼þZLD V4.60µÄVPNϵÁÐ

2020Äê12ÔµÄZLD V4.60²¹¶¡1

AP¿ØÖÆÆ÷

NXC2500

2021Äê4ÔµÄV6.10 Patch1

NXC5500

2021Äê4ÔµÄV6.10 Patch1

 

ÏÂÔØÁ´½Ó£º

https://www.zyxel.com/support/download_landing.shtml

 

0x03 ²Î¿¼Á´½Ó

https://www.zyxel.com/support/CVE-2020-29583.shtml

https://securityaffairs.co/wordpress/112877/iot/secret-backdoor-zyxel-devices.html?

https://www.eyecontrol.nl/blog/undocumented-user-account-in-zyxel-products.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29583

 

0x04 ʱ¼äÏß

2020-12-23  ZyxelÐû²¼Ç徲ͨ¸æ

2021-01-04  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png