»ªË¶Â·ÓÉÆ÷¿çÕ¾¾ç±¾¹¥»÷·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-10-26

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-18287£¬£¬ £¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬ £¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


¸Ã·ì϶ӰÏìÁË»ªË¶RT-AC58U v3.0.0.4.380_6516·ÓÉÆ÷¡£¡£¡£¡£¡£¡£¡£


·ì϶¸ÅÊö


»ªË¶RT-AC58U·ÓÉÆ÷ÊÇ̨Í廪˶µçÄԹɷÝÓÐÏÞ¹«Ë¾ËùÉè¼ÆÑз¢µÄ¼ÒÍ¥ÎÞÏß·ÓÉÆ÷£¬£¬ £¬£¬£¬£¬£¬ÊÇ»ªË¶¹Ù·½°ä²¼µÄÊ׿î¸ßͨËĺË˫ƵÎÞÏß·ÓÉÆ÷¡£¡£¡£¡£¡£¡£¡£
°²È«×êÑÐÈËÔ±·¢ÏÖ£¬£¬ £¬£¬£¬£¬£¬ÔÚ»ªË¶RT-AC58U·ÓÉÆ÷ÖдæÔÚ¿çÕ¾¾ç±¾¹¥»÷·ì϶¡£¡£¡£¡£¡£¡£¡£·ÖÎöÅú×¢£¬£¬ £¬£¬£¬£¬£¬¸Ã·ì϶ÔÊÐíÔ¶³Ì¹¥»÷ÕßÏòÉ豸עÈëËÁÒâWeb»òHTML¾ç±¾£¬£¬ £¬£¬£¬£¬£¬µ¼ÖÂLogout.asp, Main_Login.asp, apply.cgi, clients.asp, disk.asp, disk_utility.asp, or internet.aspµÈÒ³Ãæ¾ùÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£
¹úÄÚ¶³öÔÚ»¥ÁªÍøµÄ¸Ã·ì϶ÓйØÍøÂç×ʲúÉ¢²¼Í¼

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


·ì϶ÑéÖ¤


POC£º

https://github.com/remix30303/AsusLeak


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼½â¾öÉÏÊö·ì϶µÄ¹Ì¼þ¸üУ¬£¬ £¬£¬£¬£¬£¬½¨ÒéÓйØÓû§ÊµÊ±²é³­¸üС£¡£¡£¡£¡£¡£¡£
»¹Î´°ä²¼Óйطì϶µÄ²¹¶¡£¬£¬ £¬£¬£¬£¬£¬Çë¹Ø×¢¹ÙÍø¸üУºhttps://www.asus.com/Microsite/2015/networks/routerfirmware_update/
´Ë±í£¬£¬ £¬£¬£¬£¬£¬½¨ÒéÓйØÓû§Ó¦²ÉÈ¡µÄÆäËû°²È«·À»¤´ëÊ©ÈçÏ£º
£¨1£©×î´óÏ޶ȵØÏ÷¼õËùÓнÚÔìϵͳÉ豸ºÍ/»òϵͳµÄÍøÂç¶³ö£¬£¬ £¬£¬£¬£¬£¬²¢È·±£ÎÞ·¨´ÓInternet½Ó¼û¡£¡£¡£¡£¡£¡£¡£
£¨2£©¶¨Î»·À»ðǽ·À»¤µÄ½ÚÔìÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸£¬£¬ £¬£¬£¬£¬£¬²¢½«ÆäÓëÒµÎñÍøÂç¸ôÀë¡£¡£¡£¡£¡£¡£¡£

£¨3£©µ±±ØÒªÔ¶³Ì½Ó¼ûʱ£¬£¬ £¬£¬£¬£¬£¬ÇëʹÓð²È«²½ÖèÈçÐ鹹רÓÃÍøÂ磨VPN£©£¬£¬ £¬£¬£¬£¬£¬ÒªÒâʶµ½VPN¿ÉÄÜ´æÔڵķì϶£¬£¬ £¬£¬£¬£¬£¬Ð轫VPN¸üе½×îа汾¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


http://www.cnvd.org.cn/flaw/show/CNVD-2018-21251
https://nvd.nist.gov/vuln/detail/CVE-2018-18287#