¡¾Îó²îͨ¸æ¡¿Zyxel ·À»ðǽ & AP×°±¸¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2022-05-26

 

0x00 Îó²î¸ÅÊö

ºÏÇڿƼ¼(Zyxel Communications Corp.)ÊÇÒ»¼Ò¿ç¹ú¿í´ø½ÓÈë½â¾ö¼Æ»®ÌṩÉÌ¡£¡£¡£¡£¡£

2022Äê5ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬£¬ZyxelÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÆä·À»ðǽ¡¢AP ¿ØÖÆÆ÷ºÍ AP×°±¸ÖеĶà¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬ÕâЩÎó²î¿ÉÄܵ¼ÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡¢ÐÅϢй¶¡¢¾Ü¾øÐ§ÀÍ»òÏÂÁîÖ´ÐС£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

Zyxel´Ë´Î¹²ÐÞ¸´ÁËÓ°ÏìÆä¶à¸ö²úÆ·ÐͺŵÄ4¸öÎó²î£¬£¬£¬£¬£¬£¬£¬ÏêÇéÈçÏ£º

CVE-2022-0734£ºZyxel·À»ðǽ¿çÕ¾¾ç±¾Îó²î£¨ÖÐΣ£©

ZyxelijЩ·À»ðǽ°æ±¾µÄ CGI ³ÌÐòÖб£´æ¿çÕ¾¾ç±¾Îó²î£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ý¶ñÒâ¾ç±¾»ñÈ¡´æ´¢ÔÚÓû§ä¯ÀÀÆ÷ÖеÄijЩÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Èç cookie »ò»á»°ÁîÅÆ¡£¡£¡£¡£¡£

CVE-2022-26531£ºZyxel·À»ðǽ & AP×°±¸»º³åÇøÒç³öÎó²î£¨ÖÐΣ£©

ZyxelijЩ·À»ðǽ¡¢AP¿ØÖÆÆ÷ºÍAP×°±¸µÄijЩCLIÏÂÁîÖб£´æ²»×¼È·µÄÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ý¶ñÒâPayloadÔì³É»º³åÇøÒç³ö»òϵͳÍ߽⡣¡£¡£¡£¡£

CVE-2022-26532£ºZyxel·À»ðǽ & AP×°±¸ÏÂÁî×¢ÈëÎó²î£¨¸ßΣ£©

ZyxelijЩ·À»ðǽ¡¢AP¿ØÖÆÆ÷ºÍAP×°±¸µÄ¡°packet-trace¡±CLI ÏÂÁîÖб£´æÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ýÔÚÏÂÁîÖаüÀ¨È«ÐÄÉè¼ÆµÄ²ÎÊýÀ´Ö´ÐÐí§ÒâϵͳÏÂÁî¡£¡£¡£¡£¡£

CVE-2022-0910£ºZyxel·À»ðǽÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨ÖÐΣ£©

ÓÉÓÚȱ·¦Êʵ±µÄ»á¼û¿ØÖÆ»úÖÆ£¬£¬£¬£¬£¬£¬£¬ZyxelijЩ·À»ðǽ°æ±¾µÄCGI³ÌÐòÖб£´æÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ý IPsec VPN ¿Í»§¶Ë´ÓË«ÒòËØÉí·ÝÑéÖ¤½µ¼¶Îªµ¥ÒòËØÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£

 

0x02 Çå¾²½¨Òé

ÏÖÔÚÕâЩÎó²îÒѾ­ÐÞ¸´£¬£¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§²Î¿¼Ï±íʵʱÉý¼¶¸üе½ÐÞ¸´°æ±¾£º

·À»ðǽװ±¸

ÊÜÓ°Ïì°æ±¾

ÐÞ¸´°æ±¾

CVE-2022-0734

CVE-2022-26531

CVE-2022-26532

CVE-2022-0910

USG/ZyWALL

ZLD   V4.35~V4.70

ZLD   V4.09~V4.71

ZLD   V4.09~V4.71

ZLD   V4.32~V4.71

ZLD V4.72

USG FLEX

ZLD V4.50~V5.20

ZLD   V4.50~V5.21

ZLD   V4.50~V5.21

ZLD   V4.50~V5.21

ZLD V5.30

ATP

ZLD   V4.35~V5.20

ZLD   V4.32~V5.21

ZLD   V4.32~V5.21

ZLD   V4.32~V5.21

ZLD V5.30

VPN

ZLD   V4.35~V5.20

ZLD   V4.30~V5.21

ZLD   V4.30~V5.21

ZLD   V4.32~V5.21

ZLD V5.30

NSG

²»ÊÜÓ°Ïì

V1.00~V1.33   Patch 4

V1.00~V1.33   Patch 4

²»ÊÜÓ°Ïì

V1.33 Patch   5


AP ¿ØÖÆÆ÷

ÊÜÓ°Ïì°æ±¾

ÐÞ¸´°æ±¾

CVE-2022-26531 ºÍCVE-2022-26532

NXC2500

6.10(AAIG.3) ¼°¸üÔç°æ±¾

ÁªÏµÊÛºó

NXC5500

6.10(AAOS.3) ¼°¸üÔç°æ±¾


AP×°±¸

ÊÜÓ°Ïì°æ±¾

ÐÞ¸´°æ±¾

CVE-2022-26531   ºÍ CVE-2022-26532

NAP203

6.25(ABFA.7) ¼°¸üÔç°æ±¾

6.25(ABFA.8)

NAP303

6.25(ABEX.7) ¼°¸üÔç°æ±¾

6.25(ABEX.8)

NAP353

6.25(ABEY.7) ¼°¸üÔç°æ±¾

6.25(ABEY.8)

NWA50AX

6.25(ABYW.5) ¼°¸üÔç°æ±¾

6.25(ABYW.8)

NWA55AXE

6.25(ABZL.5) ¼°¸üÔç°æ±¾

6.25(ABZL.8)

NWA90AX

6.27(ACCV.2) ¼°¸üÔç°æ±¾

6.27(ACCV.3)

NWA110AX

6.30(ABTG.2) ¼°¸üÔç°æ±¾

6.30(ABTG.3)

NWA210AX

6.30(ABTD.2) ¼°¸üÔç°æ±¾

6.30(ABTD.3)

NWA1123-AC-HD

6.25(ABIN.6) ¼°¸üÔç°æ±¾

6.25(ABIN.8)

NWA1123-AC-PRO

6.25(ABHD.7) ¼°¸üÔç°æ±¾

6.25(ABHD.8)

NWA1123ACv3

6.30(ABVT.2) ¼°¸üÔç°æ±¾

6.30(ABVT.3)

NWA1302-AC

6.25(ABKU.6) ¼°¸üÔç°æ±¾

6.25(ABKU.8)

NWA5123-AC-HD

6.25(ABIM.6) ¼°¸üÔç°æ±¾

6.25(ABIM.8)

WAC500H

6.30(ABWA.2) ¼°¸üÔç°æ±¾

6.30(ABWA.3)

WAC500

6.30(ABVS.2) ¼°¸üÔç°æ±¾

6.30(ABVS.3)

WAC5302D-S

6.10(ABFH.10) ¼°¸üÔç°æ±¾

ÁªÏµÊÛºó

WAC5302D-Sv2

6.25(ABVZ.6) ¼°¸üÔç°æ±¾

6.25(ABVZ.8)

WAC6103D-I

6.25(AAXH.7) ¼°¸üÔç°æ±¾

6.25(AAXH.8)

WAC6303D-S

6.25(ABGL.6) ¼°¸üÔç°æ±¾

6.25(ABGL.8)

WAC6502D-E

6.25(AASD.7) ¼°¸üÔç°æ±¾

6.25(AASD.8)

WAC6502D-S

6.25(AASE.7) ¼°¸üÔç°æ±¾

6.25(AASE.8)

WAC6503D-S

6.25(AASF.7) ¼°¸üÔç°æ±¾

6.25(AASF.8)

WAC6553D-E

6.25(AASG.7) ¼°¸üÔç°æ±¾

6.25(AASG.8)

WAC6552D-S

6.25(ABIO.7) ¼°¸üÔç°æ±¾

6.25(ABIO.8)

WAX510D

6.30(ABTF.2) ¼°¸üÔç°æ±¾

6.30(ABTF.3)

WAX610D

6.30(ABTE.2) ¼°¸üÔç°æ±¾

6.30(ABTE.3)

WAX630S

6.30(ABZD.2) ¼°¸üÔç°æ±¾

6.30(ABZD.3)

WAX650S

6.30(ABRM.2) ¼°¸üÔç°æ±¾

6.30(ABRM.3)

 

ÏÂÔØÁ´½Ó£º

https://www.zyxel.com/

 

0x03 ²Î¿¼Á´½Ó

https://www.zyxel.com/support/multiple-vulnerabilities-of-firewalls-AP-controllers-and-APs.shtml

https://nvd.nist.gov/vuln/detail/CVE-2022-26531

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-05-26

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¼øºÚµ£±£Íø¼ò½é

¼øºÚµ£±£Íø¹«Ë¾½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬£¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬£¬£¬£¬£¬£¬£¬ÊǺ£ÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÇå¾²²úÆ·¡¢¿ÉÐÅÇå¾²ÖÎÀíÆ½Ì¨¡¢Ç徲ЧÀÍÓë½â¾ö¼Æ»®µÄ×ÛºÏÌṩÉÌ¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬£¬£¬£¬£¬£¬£¬ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÇþµÀϵͳºÍÊÖÒÕÖ§³ÖÖÐÐÄ£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£¡£¡£¡£¡£

¶àÄêÀ´£¬£¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£


¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º

image.png