TP-Link½¨¸´Archer·ÓÉÆ÷Éí·ÝÑéÖ¤ÈÆ¹ý·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2019-12-17

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-7405£¬£¬ £¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬ £¬£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


Archer C5 V4¡¢Archer MR200v4¡¢Archer MR6400v4ºÍArcher MR400v3·ÓÉÆ÷


·ì϶¸ÅÊö


TP-Link½¨¸´²¿ÃÅArcher·ÓÉÆ÷Öеݲȫ·ì϶£¬£¬ £¬£¬£¬ £¬£¬£¬¸Ã·ì϶ʹµÃ¹¥»÷ÕßÄܹ»ÎÞÐèÖÎÀíÔ±ÃÜÂë¼´¿ÉÊÕÊÜÉ豸¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý·¢ËÍ×Ö·û´®³¤¶È³¬¹ýÔÊÐíµÄ×Ö½ÚÊýµÄHTTPÒªÇ󣬣¬ £¬£¬£¬ £¬£¬£¬Ê¹µÃÓû§ÃÜÂë±»´úÌæÎª¿ÕÖµ£¬£¬ £¬£¬£¬ £¬£¬£¬´Ó¶ø»ñµÃ·ÓÉÆ÷µÄadminȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷»¹»áʹºÏ·¨Óû§±»Ëø¶¨£¬£¬ £¬£¬£¬ £¬£¬£¬²¢ÇÒÎÞ·¨Í¨¹ýÓû§½çÃæµÇ¼Web·þÎñ£¨ÃÜÂë±»Çå¿Õ¶øÓû§²¢²»ÖªÇ飩¡£¡£¡£¡£¡£¡£¡£¡£


Ö»¹Ü´æÔÚÄÚÖÃÑéÖ¤£¬£¬ £¬£¬£¬ £¬£¬£¬µ«Á˾ÖÒÀÈ»Èç´Ë£¬£¬ £¬£¬£¬ £¬£¬£¬ÓÉÓÚÄÚÖÃÑéÖ¤½ö»á²é³­ÒýÓÃµÄ HTTP ±êÍ·£¬£¬ £¬£¬£¬ £¬£¬£¬µ¼Ö¹¥»÷Õßͨ¹ýʹÓÃÓ²±àÂëµÄ tplinkwifi.netÖµÓÕÆ­Â·ÓÉÆ÷µÄ httpd ·þÎñÒÔΪҪÇóÊǺϷ¨µÄ¡£¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



ÈçÏÂͼ£¬£¬ £¬£¬£¬ £¬£¬£¬½öʹÓá° admin¡±×÷ΪÓû§Ãû¼´¿É½Ó¼ûTELNETºÍFTP£¬£¬ £¬£¬£¬ £¬£¬£¬¶øÎÞÐèÊäÈëÈκÎÃÜÂ룬£¬ £¬£¬£¬ £¬£¬£¬Ä¬ÈÏÇé¿öÏ£¬£¬ £¬£¬£¬ £¬£¬£¬¸ÃÓû§ÃûÊÇÉ豸ÉÏΨһ¿ÉÓõÄÓû§¡£¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



·ì϶ÑéÖ¤


POC£ºhttps://securityintelligence.com/posts/tp-link-archer-router-vulnerability-voids-admin-password-can-allow-remote-takeover/¡£¡£¡£¡£¡£¡£¡£¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѽ¨¸´·ì϶£¬£¬ £¬£¬£¬ £¬£¬£¬½¨ÒéÓû§¾¡¿ì×°Öò¹¶¡£¡£¡£¡£¡£¡£¡£¡£º


Archer C5 V4£ºhttps://static.tp-link.com/2019/201909/20190917/Archer_C5v4190815.rar

Archer MR200v4£ºhttps://static.tp-link.com/2019/201909/20190903/Archer%20MR200(EU)_V4_20190730.zip

Archer MR6400v4£ºhttps://static.tp-link.com/2019/201908/20190826/Archer%20MR6400(EU)_V4_20190730.zip

Archer MR400v3£ºhttps://static.tp-link.com/2019/201908/20190826/Archer%20MR400(EU)_V3_20190730.zip


²Î¿¼Á´½Ó


https://securityintelligence.com/posts/tp-link-archer-router-vulnerability-voids-admin-password-can-allow-remote-takeover/