Zyxel½¨¸´ÍøÂç´æ´¢²úÆ·ÖеÄ0day·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-02-27

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-9054£¬£¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º10£¬£¬£¬£¬ £¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÔËÐй̼þ°æ±¾5.21¼°¸üµÍ°æ±¾µÄNAS²úÆ·¡£¡£¡£¡£¡£


ÔËÐй̼þ°æ±¾ZLD V4.35²¹¶¡0µ½ZLD V4.35²¹¶¡2µÄUTM¡¢ATPºÍVPN·À»ðǽ¡£¡£¡£¡£¡£ZLD V4.35²¹¶¡0֮ǰµÄ¹Ì¼þ°æ±¾²»ÊÜÓ°Ïì


·ì϶¸ÅÊö


ÍøÂçÉ豸³§ÉÌZyxel°ä²¼Á˶à¿îÍøÂç´ÓÊô´æ´¢£¨NAS£©É豸µÄ²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬ £¬£¬£¬½¨¸´Ò»¸öÒÑÔâµ½ÍøÂç·¸×ï·Ö×ÓÀûÓõij¬Î£·ì϶¡£¡£¡£¡£¡£


¸Ã·ì϶±àºÅΪCVE-2020-9054£¬£¬£¬£¬ £¬£¬£¬ÊÇÒ»¸öÎÞÐèÉí·ÝÈÏÖ¤¼´¿ÉÀûÓõÄÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚweblogin.cgiÎļþÖУ¬£¬£¬£¬ £¬£¬£¬Ô´ÓÚCGI¿ÉÖ´ÐÐÎļþδÄܰ²Í׵عýÂËÏòÆä´«µÝµÄusername²ÎÊý¡£¡£¡£¡£¡£


ÃÀ¹úCERT/CC°µÊ¾£¬£¬£¬£¬ £¬£¬£¬ÈôÊÇÓû§ÃûÖÐÔ̺¬ÁËÌØ¶¨×Ö·û£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÒÔwebserverµÄȨÏÞ×¢ÈëºÅÁî¡£¡£¡£¡£¡£½Ó×Å£¬£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓÃÉ豸ÉÏÔ̺¬µÄÒ»¸ösetuidʵÓ÷¨Ê½ÒÔrootȨÏÞÔËÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£


ZyxelÔÚ°²È«²¼¸æÖÐÚ¹Êͳƣ¬£¬£¬£¬ £¬£¬£¬ÔËÐÐ5.21¼°Ö®Ç°°æ±¾¹Ì¼þµÄZyxelNAS²úÆ·µÄweblogin.cgi·¨Ê½Öз¢ÏÖÁËÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¸Ã·¨Ê½¶ÌȱÉí·ÝÈÏÖ¤£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉÀûÓ÷ì϶ͨ¹ý×¢ÈëOSºÅÁîÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£


Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÔìµÄHTTP POST»òGETÒªÇóÔÚ´àÈõµÄZyxelÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¼´±ã¹¥»÷ÕßûÓÐÖ±½ÓÏνÓÉ豸£¨ÈôÊÇÉ豸ûÓж³öÔÚÍøÂçÖУ©£¬£¬£¬£¬ £¬£¬£¬µ«ÊÇÊܺ¦ÕßÏνÓÁ˶ñÒâµÄÍøÕ¾£¬£¬£¬£¬ £¬£¬£¬Ò²¿É´¥·¢¸Ã·ì϶¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


¸Ã·ì϶µÄexploitÔÚµØÏÂÂÛ̳ÏúÊÛÒÑÓÐÒ»¶Î¹¦·ò£¬£¬£¬£¬ £¬£¬£¬±ê¼Û2ÍòÃÀÔª¡£¡£¡£¡£¡£×¨ÃŲ¿ÊðÀÕË÷Èí¼þµÄÍÅ»ïÒѾ­¶Ô¸Ãexploit°µÊ¾ÐËÖ£¬£¬£¬£¬ £¬£¬£¬EmotetÍÅ»ïÒ²³ïË㽫¸Ãexploit·Åµ½ËûÃǵĶñÒâÈí¼þÖÓ×£¡£¡£¡£¡£


½¨¸´½¨Òé


Zyxel°ä²¼ÁËËÄ¿î´àÈõµÄÉ豸µÄ²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬ £¬£¬£¬Ò²¾ÍÊÇNAS326£¬£¬£¬£¬ £¬£¬£¬NAS520£¬£¬£¬£¬ £¬£¬£¬NAS540ºÍNAS542£¬£¬£¬£¬ £¬£¬£¬ÒÔ¼°UTM¡¢ATPºÍVPN·À»ðǽµÄ²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬ £¬£¬£¬Á´½Ó£ºhttps://www.zyxel.com/support/remote-code-execution-vulnerability-of-NAS-products.shtml¡£¡£¡£¡£¡£


»¹ÓÐ10¿îNAS²úÆ·²»Ôٵõ½ZyxelÖ§³Ö£¬£¬£¬£¬ £¬£¬£¬½«²»»áÊÕµ½²¹¶¡¡£¡£¡£¡£¡£ÕâЩ²úÆ·Ô̺¬

NSA210£¬£¬£¬£¬ £¬£¬£¬NSA220£¬£¬£¬£¬ £¬£¬£¬NSA220+£¬£¬£¬£¬ £¬£¬£¬NSA221£¬£¬£¬£¬ £¬£¬£¬NSA310£¬£¬£¬£¬ £¬£¬£¬NSA310S£¬£¬£¬£¬ £¬£¬£¬NSA320£¬£¬£¬£¬ £¬£¬£¬NSA320S£¬£¬£¬£¬ £¬£¬£¬NSA325ºÍNSA325v2¡£¡£¡£¡£¡£


ÕâЩÉ豸µÄ»º½â´ëÊ©Ô̺¬À¹½Ø¶Ô web ½Ó¿Ú£¨80/tcp ºÍ 443/tcp£©µÄ½Ó¼ûȨÏÞ²¢È·±£¸Ã NAS δ±»Â¶³öÔÚ»¥ÁªÍøÉÏ¡£¡£¡£¡£¡£ÈçÓпÉÄÜ£¬£¬£¬£¬ £¬£¬£¬Ôò½«ÆäÏνӵ½°²È«Â·ÓÉÆ÷»ò²¿Êð·À»ðǽ½øÇ°½øÒ»²½·À»¤¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.securityweek.com/zyxel-devices-can-be-hacked-dns-requests-hardcoded-credentials