ÐÅÈñWACºÅÁî×¢Èë·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-05-21

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-9161£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


ÐÅÈñWAC 3.7.4.2¼°Ö®Ç°°æ±¾


·ì϶¸ÅÊö


Sundray WLAN Controller£¨ÐÅÈñWAC£©ÊÇÖйúÐÅÈñÍø¿Æ¼¼Êõ£¨Sundray£©¹«Ë¾µÄÒ»Ì×ÎÞÏß¾ÖÓòÍø½ÚÔìÆ÷Èí¼þ¡£¡£¡£¡£¡£¡£¡£¡£ÐÅÈñ¿Æ¼¼ÖØÒªÒµÎñΪÆóÒµ¼¶ÎÞÏßÍøÂç¡¢ÎïÁªÍøÒÔ¼°ÖÇÄÜ»¥»»»ú²úÆ·µÄ¿ª·¢¡¢ÀûÓ㬣¬ £¬£¬£¬ÐÐÒµ¿Í»§×ÜÁ¿³¬¹ý55000¼Ò¡£¡£¡£¡£¡£¡£¡£¡£¾ÝIDCÊý¾ÝÏÔʾ£¬£¬ £¬£¬£¬2018Ä꣬£¬ £¬£¬£¬ÐÅÈñÎÞÏßÔÚÖйúÆóÒµ¼¶WLANÊг¡ÅÅÃûµÚÈý¡£¡£¡£¡£¡£¡£¡£¡£


ÎÞÏß½ÚÔìÆ÷Ó²¼þ(AC)´æÔÚÒ»¸öÎÞÐèµÇ¼µÄRCE·ì϶²¢¿Éͨ¹ýWebUIÖ°ÄÜȱµãÖ±½Ó»ñÈ¡É豸µÄroot½ÚÔìȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£ACÉ豸ÍùÍùÊÇÒ»¸öÆóÒµ°ì¹«ÍøÂçµÄÉÏÍøÈë¿Ú£¬£¬ £¬£¬£¬¶Ô½ÓÆóÒµÈÏ֤ϵͳ£¨LDAPµÈ£©£¬£¬ £¬£¬£¬²¢¿ÉÄÜÁ¬Í¨¸÷³ö²ú¡¢°ì¹«ÍøÂ磨OA¡¢GitlabµÈ£©¡£¡£¡£¡£¡£¡£¡£¡£Òò¶ø£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉÒÀ´Ë·ì϶»ñÈ¡ÆóÒµÄÚÍøÖÜÓεÄõè¾¶£¬£¬ £¬£¬£¬½ø¶ø·¢Õ¹¶ÔÆóÒµÄÚÍøµÄ³ÖÐøÉøÈëºÍ¹¥»÷£¨APT£©¡£¡£¡£¡£¡£¡£¡£¡£


Ô¶³Ì¹¥»÷Õ߿ɽèÖúnginx_webconsole.php°üÍ·ÖеÄshellÔª×Ö·û¶ÁÈ¡´øÓÐadminÃÜÂëµÄetc/config/wac/wns_cfg_admin_detail.xmlÎļþ£¬£¬ £¬£¬£¬ÀûÓø÷ì϶»ñȡϵͳµÄÈ«ÊýȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC¡¢EXP¡£¡£¡£¡£¡£¡£¡£¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬ £¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º

http://www.sundray.com.cn


²Î¿¼Á´½Ó


http://www.cnvd.org.cn/flaw/show/CNVD-2019-07679
https://nvd.nist.gov/vuln/detail/CVE-2019-9161