8827Ì«Ñô¼¯ÍÅADLab£ºÐÛÂõ¶à¸öÉãÏñÍ··ì϶ÖҸ漰½¨¸´£¨¸½¹¤¾ß£©
°ä²¼¹¦·ò 2018-10-19½üÈÕ£¬£¬£¬£¬£¬£¬¹ú±í°²È«×êÑÐÈËÔ±¹«¿ªÁËÐÛÂõ²úÆ·µÄ¶à¸ö°²È«·ì϶£¨CVE-2018-17915¡¢CVE-2018-17917¡¢CVE-2018-17919£©£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶¿ÉÓ°ÏìÐÛÂõ¹«Ë¾µÄÖØÒªÉãÏñÍ·²úÆ·¼°ÓйصÄÉãÏñÍ·Ä£×é¡£¡£¡£¡£¡£Í¨¹ýÕâЩ·ì϶£¬£¬£¬£¬£¬£¬¶ñÒâ¹¥»÷ÕßÄܹ»Í¨¹ýÄÚ±íÍø½Ø»ñÉãÏñÍ·ÊÓÆµÔ´¡¢×°ÖöñÒâ´úÂë¡¢ÌáÒé´ó¹æÄ£ÍøÂç¹¥»÷µÈÐÐΪ¡£¡£¡£¡£¡£
ͨ¹ýCVE-2018-17915£¨ÔÆÆ½Ì¨É豸ÐòÁкÅÐÅϢй¶£©ºÍCVE-2018-17919£¨ÄÚÖÃdefaultÕË»§£©µÄ×éºÏ£¬£¬£¬£¬£¬£¬Ö»ÓÐÉ豸ÄܽӼû»¥ÁªÍø£¬£¬£¬£¬£¬£¬¹¥»÷Õß¾ÍÄܹ»Ô¶³Ì¶ÔÄÚÍøÉ豸ÌáÒé¹¥»÷£¬£¬£¬£¬£¬£¬Ê¹µÃCVE-2018-17919µÄ·ì϶ӰÏìÃæ½øÒ»²½À©´ó¡£¡£¡£¡£¡£
Ϊ±£ÏÕ¹«¹²°²È«£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅADLab½¨Ò飺
- ÔÚ·ì϶δÆëÈ«½¨¸´Ç°£¬£¬£¬£¬£¬£¬É豸ʹÓ÷½Ó¦ÏÞ¶ÈÎÊÌâÉ豸µÄ»¥ÁªÍø½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£
- ÔÚ¹«¿ªµÄ·ì϶ÖÐÓ°Ïì×î´óµÄÊÇCVE-2018-17919£¨ÄÚÖÃdefaultÕË»§£©£¬£¬£¬£¬£¬£¬Ä¿Ç°·ì϶ÒѾ¹«¿ª£¬£¬£¬£¬£¬£¬´óÁ¿µÄÔÚÍøÉ豸Êܵ½°²È«Íþв£»£»£»£»£»8827Ì«Ñô¼¯ÍÅADLabµÚÒ»¹¦·ò°ä²¼ÁËCVE-2018-17919·ì϶½¨¸´¹¤¾ß£¬£¬£¬£¬£¬£¬ÓйØÓû§Ç뾡¿ì¿ÉʹÓô˹¤¾ß¶Ô·ì϶½øÐмì²âÓ뽨¸´¡£¡£¡£¡£¡£
¶þ¡¢·ì϶ӰÏìÃæ
ƾ¾Ý2018Äê3ÔÂCNCERT°ä²¼µÄ¡¶ÁªÍøÊÓÆµ¼à¿ØÏµÍ³ÍøÂç°²È«Ì¬ÊÆ»ã±¨¡·£¬£¬£¬£¬£¬£¬ÐÛÂõÒÔ6.25%µÄÕ¼±ÈÃûÁÐÈ«ÇòµÚËÄ£»£»£»£»£»Í¬Ê±£¬£¬£¬£¬£¬£¬ÐÛÂõÉãÏñÍ·Ä£×鹿»®±»´óÁ¿³§ÉÌѡȡ£¬£¬£¬£¬£¬£¬½ö²¿ÃÅͨ´ïµÄOEM³§¼ÒºÍÖÇÄܼҾӳ§¼ÒÒѳ¬¹ý°Ù¼Ò£»£»£»£»£»Òò¶ø³ýÐÛÂõÆ·ÅÆ±í£¬£¬£¬£¬£¬£¬ÆäËûÆ·ÅÆµÄÉãÏñÍ·ÓйØÉ豸ҲӦÒýÆð¸ß¶ÈÆ÷³Á¡£¡£¡£¡£¡£Æ¾¾Ý¼à²âÊý¾Ý£¬£¬£¬£¬£¬£¬Ä¿Ç°ÊÜÓ°ÏìµÄÔÚÍøÉ豸ÊýÁ¿ÔÚ°ÙÍòÒÔÉÏ¡£¡£¡£¡£¡£
Èý¡¢·ì϶½éÉÜ
ÐÛÂõÊÇ2016ÄêmiraiľÂí´ó¹æÄ£DDoS¹¥»÷ÊÂÎñµÄÖØÒªÊÜÓ°Ïì³§¼Ò£¬£¬£¬£¬£¬£¬½üÆÚ¹ú±í°²È«×êÑÐÈËԱа䲼µÄÓйطì϶Çé¿öÈçÏ£º
|
CVE񅧏 |
ÎÊÌâ |
·çÏÕ |
|
CVE-2018-17915 |
ÔÆÆ½Ì¨µÄÉ豸ÐòÁкÅÄܹ»Í¨¹ýÉ豸µÄMACµØÖ·ÍÆËã³ö |
¹¥»÷ÕßÄܹ»Í¨¹ýÐÛÂõÉ豸µÄMACµØÖ·ÍÆËã³öÉ豸µÄÔÆÆ½Ì¨ÕË»§£¬£¬£¬£¬£¬£¬²¢Äܹ»»ñµÃÕË»§µÄÔÚÏßÇé¿ö¡£¡£¡£¡£¡£ |
|
ÎÞ |
adminÓû§´æÔÚ³õʼÃÜÂë |
ÔÚ×îÖÕÓû§Ã»ÓÐÅú¸ÄadminÓû§³õʼÃÜÂëµÄÇé¿öÏ£¬£¬£¬£¬£¬£¬¸Ã³õʼÃÜÂëÄܹ»±»¹¥»÷ÕßÔ¶³ÌÀûÓ㬣¬£¬£¬£¬£¬ÆëÈ«½ÚÔìÉãÏñÍ·£¬£¬£¬£¬£¬£¬×°ÖöñÒâÈí¼þ¡£¡£¡£¡£¡£ |
|
CVE-2018-17919 |
ÄÚÖÃdefaultÕË»§ |
¹¥»÷Õß¿ÉÀûÓÃdefaultÕË»§¼°ÆäÄÚÖõÄÃÜÂ룬£¬£¬£¬£¬£¬Ô¶³ÌÇÔÌýÊÓÆµÔ´¡£¡£¡£¡£¡£ |
|
CVE-2018-17917 |
ͨѶͨ·¶ÌȱÓÐЧµÄ¼ÓÃܱ£»£»£»£»£»¤ |
¹¥»÷Õß¿Éͨ¹ý¼àÌýÉãÏñÍ·µÄÍøÂçͨѶ£¬£¬£¬£¬£¬£¬»ñÈ¡ÉãÏñÍ·µÄÊÓÆµµã²¥µØÖ·£¬£¬£¬£¬£¬£¬´Ó¶øÇÔÌýÊÓÆµÔ´ºÍÓû§µÇ½ƾ֤¡£¡£¡£¡£¡£ |
|
ÎÞ |
¹Ì¼þµÄÆëÈ«ÐÔ¼°°²È«ÐÔ¶ÌȱÓÐЧ±£»£»£»£»£»¤»úÔì |
¹¥»÷Õß¿ÉÔÚ»ñµÃµÇ½ƾ֤µÄÇé¿öÏ£¬£¬£¬£¬£¬£¬»ú¹Ø¶ñÒâ¹Ì¼þ£¬£¬£¬£¬£¬£¬´Ó¶øÈÃÉãÏñÍ·Ö´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£ |
ÒÔÉÏ·ì϶£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅADLab¾ùÔÚÓйØÐͺŵÄ×îй̼þ°æ±¾ÉϽøÐÐÁËÑéÖ¤¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬Í¨¹ý¶Ô³§¼ÒµÄ¹ÙÍøÉÏÆäËûÐͺŵĹ̼þ½øÐзÖÎö£¬£¬£¬£¬£¬£¬·¢ÏÖÓйطì϶ÎÊÌâÔÚÆäËû°²·ÀÉãÏñÍ·µÄÐͺÅÉÏÒ²´æÔÚ£¬£¬£¬£¬£¬£¬·ì϶ӰÏìÁìÓò±ÈÁ¦¿í·º¡£¡£¡£¡£¡£¾ÑéÖ¤£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýÄÚ±íÍø½Ø»ñÉãÏñÍ·ÊÓÆµÔ´¡¢×°ÖöñÒâ´úÂë¡¢ÀûÓ÷ì϶ÌáÒé´ó¹æÄ£ÍøÂç¹¥»÷µÈÐÐΪ¡£¡£¡£¡£¡£
ËÄ¡¢·ì϶Ӧ¶ÔÕ½Êõ½¨Òé
4.1 CVE-2018-17919·ì϶¼ì²âÓ뽨¸´
4.1.1 ·ì϶µÀÀí
ÔÚÉãÏñÍ·¹Ì¼þµÄÓйغ¯ÊýÖдæÔÚÎÊÌâ´úÂ룬£¬£¬£¬£¬£¬ÐÛÂõÉãÏñÍ·ÔÚ³ö³§ÉèÖÃʱԤÖÃÁËdefaultÕʺż°Ä¬ÈÏÃÜÂ룬£¬£¬£¬£¬£¬¸ÃÕ˺ÅÔÚ¿Í»§¶ËÎÞ·¨½øÐÐɾ³ý£¬£¬£¬£¬£¬£¬Ò²²»»áÏÔʾÔÚ¿Í»§¶Ë¡£¡£¡£¡£¡£
4.1.2 ·ì϶¼ì²âÓ뽨¸´
Õë¶Ô´Ë·ì϶£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅADLabµÚÒ»¹¦·ò°ä²¼ÁË·ì϶½¨¸´¹¤¾ß£¬£¬£¬£¬£¬£¬ÓйØÓû§¿ÉʹÓøù¤¾ß½øÐмì²âÓ뽨¸´¡£¡£¡£¡£¡££¨ÇëÔÚ¹«¼ÒºÅÖз¢Ë͹ؼü´Ê£ºXM¹¤¾ß£¬£¬£¬£¬£¬£¬»ñÈ¡½¨¸´¹¤¾ß¡£¡£¡£¡£¡£ÈçʹÓÃÖÐÓöµ½ÎÊÌ⣬£¬£¬£¬£¬£¬Ç뽫É豸Ðͺź͹̼þ°æ±¾ºÅ·î¸æÎÒÃÇ£©
1.ÏÂÔØfix_tools.exe¡£¡£¡£¡£¡£
È磺fix_tools.exe 192.168.0.88 admin 123456
[*] vuln(cve-2018-17919) found!¡±
[*] Do you want to fix it?(y/n):
ÊäÈëy,¼´ÆðÍ·½¨¸´·ì϶¡£¡£¡£¡£¡£
[*] vuln fix success!!!!!!!!!
°ÑÎÈ£ºµ±Óû§¶ÔÉãÏñÍ·½øÐи´Ô³ö³§ÉèÖÃʱ£¬£¬£¬£¬£¬£¬ÓÉÓÚdefaultÕË»§³Áб»¹Ì¼þдÈ룬£¬£¬£¬£¬£¬Óû§±ØÒª³ÁÐÂÖ´ÐÐfix_tools¹¤¾ß½¨¸´¡£¡£¡£¡£¡£
[!] vuln not found
½¨¸´¹¤¾ßÔÚÒÔÏÂÉ豸²âÊÔͨ¹ý£º
[*] HardWare= RM50H20L_8188EU_S38
SoftWareVersion= V4.02.R12.C4420813.10002.144002.00000
[*] HardWare= 53H13-E_18EV200_8188EU_S38
SoftWareVersion= V4.02.R12.A6420240.10002.140802.00000
Ϊ±£ÏÕ¹«¹²°²È«£¬£¬£¬£¬£¬£¬Ôü×Ò·ì϶µÄ¼ì²â²½ÖèÔݲ»¹«¿ª£»£»£»£»£»ÓйØÓû§¿É²Î¿¼ÈçÏ»º½â½¨Ò飬£¬£¬£¬£¬£¬Ó¦¶Ô¿ÉÄܲúÉúµÄ¹¥»÷ÊÂÎñ£º
- ͨ¹ý¿Í»§¶Ë¶ÔadminÓû§ÉèÖø´ÔÓÃÜÂ룬£¬£¬£¬£¬£¬Ô¤·ÀadminȨÏÞ±»¹¥»÷Õß»ñµÃ¡£¡£¡£¡£¡£
- ͨ¹ý·ÓÉÆ÷ÉèÖÃÏÞ¶ÈÕ½Êõ£¬£¬£¬£¬£¬£¬¹Ø¹ØÉãÏñÍ·µÄ»¥ÁªÍø½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬Ö»ÄÜͨ¹ýÄÚÍø½Ó¼ûÉãÏñÍ·¡£¡£¡£¡£¡£
- ÔÚ³§¼ÒÌṩеķì϶²¹¶¡ºó£¬£¬£¬£¬£¬£¬ÊµÊ±¸üÐÂÉãÏñÍ·¹Ì¼þ²¹¶¡¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó£º
¡¾1¡¿ÁªÍøÊÓÆµ¼à¿ØÏµÍ³ÍøÂç°²È«Ì¬ÊÆ»ã±¨
https://www.ics-cert.org.cn/portal/page/131/be9def54499644afb6ce4b119e5e7d42.html
¡¾2¡¿ÃÀ¹ú¹¤Òµ»¥ÁªÍø°²È«ÏìÓ¦ÖÐÐIJ¼¸æ
https://ics-cert.us-cert.gov/advisories/ICSA-18-282-06


¾©¹«Íø°²±¸11010802024551ºÅ