CDATA OLTsÖжà¸ö0day·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-07-08
0x00 ·ì϶¼ò½é
2020Äê7ÔÂ7ÈÕ,×êÑÐÈËÔ±PierreÅû¶ÁËCDATA OLTÖдæÔڵĶà¸ö0day·ì϶£¬£¬£¬£¬£¬£¬£¬¶Ô²úÆ·µÄ¶à¸ö°æ±¾¶¼ÓÐÓ°Ïì¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÒÔΪÕâЩºóÃÅÓ¦ÊÇCDATAÓÐÒ⿪·¢µÄ£¬£¬£¬£¬£¬£¬£¬Òò¶øÅû¶·ì϶µÄÈ«Êýϸ½Ú£¬£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶µÄCVEÔÝδ·ÖÅä¡£¡£¡£¡£¡£
CDATA OLTÊÇOEM FTTH OLT£¬£¬£¬£¬£¬£¬£¬Éæ¼°Cdata¡¢OptiLink¡¢V-SOL CNºÍBLIYµÈÆ·ÅÆ¡£¡£¡£¡£¡£Ò»Ð©É豸֧³Ö¶à¸ö10 GbÉÏÐÐÁ´Â·£¬£¬£¬£¬£¬£¬£¬²¢Ìṩ¶à´ï1024¸öONT£¨¿Í»§¶Ë£©µÄInternetÏνӡ£¡£¡£¡£¡£
FTTH£¨Fiber To The Home£©£¬£¬£¬£¬£¬£¬£¬¼´¹âÏ˵½»§ÊÇÖ¸½«¹âÍøÂçµ¥Ôª£¨ONU£©×°ÖÃÔÚס¼ÒÓû§»òÆóÒµÓû§´¦£¬£¬£¬£¬£¬£¬£¬Êǹâ½ÓÈëϵÁÐÖÐ×î¿¿½üÓû§µÄ¹â½ÓÈëÍøÀûÓÃÀàÐÍ¡£¡£¡£¡£¡£FTTHµÄ¹âÏ˽ÓÈë¼¼ÊõÓкöàÖÖ£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÒ»ÖÖÊÇGPON¡£¡£¡£¡£¡£GPON FTTH¼«¶ÈÊ¢ÐУ¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËü¼ÛÖµ±ãÒË£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÔÊÐíÈËÃǼ±¾çÏÂÔØºÏ·¨µÄÊÓÆµµã²¥¡£¡£¡£¡£¡£
×êÑÐÈËԱʹÓÃ×îй̼þ°æ±¾£¨V1.2.2ºÍ2.4.05_000¡¢2.4.04_001ºÍ2.4.03_000£©ÔÚ³¢ÊÔÊÒ»·¾³ÖÐÑéÖ¤ÁËÕë¶ÔFD1104BºÍFD1108SN OLTµÄ·ì϶¡£¡£¡£¡£¡£
ͨ¹ý¾²Ì¬·ÖÎö£¬£¬£¬£¬£¬£¬£¬ÕâЩ·ìÏ¶ËÆºõÒ²»áÓ°ÏìËùÓпÉÓõÄOLTÄ£ÐÍ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ´úÂë¿âÀàËÆ£º
? 72408A
? 9008A
? 9016A
? 92408A
? 92416A
? 9288
? 97016
? 97024P
? 97028P
? 97042P
? 97084P
? 97168P
? FD1002S
? FD1104
? FD1104B
? FD1104S
? FD1104SN
? FD1108S
? FD1204S-R2
? FD1204SN
? FD1204SN-R2
? FD1208S-R2
? FD1216S-R1
? FD1608GS
? FD1608SN
? FD1616GS
? FD1616SN
? FD8000
´Ó·ÖÎöµÄ¶þ½øÔìÎļþÖУ¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÌáÈ¡ÁËÓйØOEM´úÀíÉ̵ÄÐÅÏ¢£º
´ÓͼÖÐÄܹ»¿´µ½£¬£¬£¬£¬£¬£¬£¬¸Ã´úÀíÉÌΪÎ÷µÏÌØ£¨CDATA£©£¬£¬£¬£¬£¬£¬£¬Àö½ÊÐÎ÷µÏÌØ¿Æ¼¼ÓÐÏÞ¹«Ë¾ÊÇÒ»¼ÒרһÓÚÌṩ¿í´øÍøÂç½ÓÈëÉ豸µÄ¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£¹«Ë¾µÄÖØÒª²úÆ·Ô̺¬GPON¡¢EPONÍøÂçÉ豸¡¢EOCÍøÂçÉ豸¡¢CATV¹â´«ÊäÉ豸¡£¡£¡£¡£¡£
0x01 ·ì϶ÏêÇé
Õâ´Î·¢Ïֵķì϶Ô̺¬telnetºóÃÅ¡¢Æ¾Ö¤ÐÅϢй©ºÍÃ÷ÎÄÌåʽƾ֤£¨telnet£©¡¢ÓµÓÐrootÌØÈ¨µÄEscape Shell¡¢Ô¤Éí·ÝÑéÖ¤Ô¶³ÌDoS¡¢Æ¾Ö¤ÐÅϢй©ºÍÃ÷ÎÄÆ¾Ö¤£¨HTTP£©¡¢Èõ¼ÓÃÜËã·¨ºÍÖÎÀí½çÃæ²»°²È«£¬£¬£¬£¬£¬£¬£¬ÏÂÃæ½øÐоßÌå½éÉÜ¡£¡£¡£¡£¡£
1. telnetºóÃÅ
¹¥»÷ÕßÄܹ»´ÓWAN½Ó¿ÚºÍFTTH LAN½Ó¿Ú½Ó¼ûtelnet·þÎñ£¬£¬£¬£¬£¬£¬£¬»ñµÃÖÎÀíÔ±CLI½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£·ÖÆçµÄ¹Ì¼þÓÐ·ÖÆçµÄÓ²±àÂëºóÃÅÆ¾Ö¤£¬£¬£¬£¬£¬£¬£¬²Î¿¼ÈçÏ£º
ÒÔǰµÄ°æ±¾Äܹ»Í¨¹ýÒÔÏ·½Ê½µÇ¼£º
login: suma123¡£¡£¡£¡£¡£
password: panger123
×îеÄа汾Äܹ»Í¨¹ýÒÔÏ·½Ê½µÇ¼£º
login: debug
password: debug124
login: root
password: root126
login: guest
password: [empty]
ƾ֤ÒÑ´Óоɹ̼þÓ³ÏñÖÐÌáÈ¡¡£¡£¡£¡£¡£
ƾ¾Ý·ÖÆçµÄ¹©¸øÉ̺͹̼þ°æ±¾£¬£¬£¬£¬£¬£¬£¬CLIµÄ±í¹Û¿ÉÄÜÓÐËù·ÖÆç£¬£¬£¬£¬£¬£¬£¬µ«½Ó¼ûÒÀÈ»ÓÐЧ¡£¡£¡£¡£¡£
ʹÓÃsuma123/panger123£º
ʹÓÃguest/[empty]£º
ʹÓÃroot/root126£º
ʹÓÃdebug/debug124£º
ÓÐÁËÕâЩ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¾ÍÄܹ»¶Ô²úÆ·½øÐÐÅäÖᣡ£¡£¡£¡£
2. ƾ֤ÐÅϢй©ºÍÃ÷ÎÄÌåʽƾ֤£¨telnet£©
ÎÒÃÇÈç¹û¹¥»÷ÕßÒѾӵÓÐCLI½Ó¼ûȨÏÞ£¨Äܹ»Í¨¹ýʹÓÃtelnetµÄBackdoor½Ó¼ûÀ´ÊµÏÖ£©¡£¡£¡£¡£¡£
¹¥»÷Õß¿ÉÔÚCLIÖÐÔËÐкÅÁî»ñÈ¡ÖÎÀíԱʹ´¦£º
3. ÓµÓÐrootÌØÈ¨µÄEscape Shell
ÎÒÃÇÈç¹û¹¥»÷ÕßÓµÓÐCLI½Ó¼ûȨÏÞ£¨Äܹ»Í¨¹ýʹÓÃtelnetµÄBackdoor½Ó¼ûÀ´ÊµÏÖ£©¡£¡£¡£¡£¡£
CLIÖÐÓкÅÁî×¢ÈëÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÒÔrootȨÏÞÖ´ÐкÅÁî¡£¡£¡£¡£¡£
ºÅÁî×¢ÈëλÓÚTFTPÏÂÔØÅäÖò¿ÃÅ¡£¡£¡£¡£¡£
ÎÒÃÇʹÓÃmetasploitÔÚ192.168.1.101ÉÏÆô¶¯TFTP·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬²¢½Ó¹Ü×¢ÈëºÅÁ£¬£¬£¬£¬£¬£¬Á˾ÖÈçÏ£º
ÔÚOLTÉÏ£º
ÔÚ¹¥»÷ÕßÍÆËã»úÉÏÔËÐеÄTFTP·þÎñÆ÷ÉÏ£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÊÕµ½ºÅÁîµÄÊä³öcat /proc/cpuinfo£º
Ò²Äܹ»ÀûÓÃǶÈëʽWeb·þÎñÆ÷À´Ð¹Â¶ÐÅÏ¢£º
ÔÚOLTÉÏ£º
ÔÚ¹¥»÷Õß»úеÉÏ£º
´Ë±í£¬£¬£¬£¬£¬£¬£¬»¹ÓкöàºÅÁî¶¼Äܹ»ÒÔrootȨÏÞÖ´ÐУ¬£¬£¬£¬£¬£¬£¬¾ßÌåÈçÏ£º
4. Ô¤Éí·ÝÑéÖ¤Ô¶³ÌDoS
¹¥»÷ÕßÄܹ»´ÓWAN½Ó¿ÚºÍFTTH LAN½Ó¿Ú½Ó¼ûtelnet·þÎñ£¬£¬£¬£¬£¬£¬£¬Ê¹ÓûùÓÚIA¡¢»úе½ø½¨ºÍshawarmaµÄÍÌͼ¼Êõ£¬£¬£¬£¬£¬£¬£¬³ÁÆôËùÓÐOLT¡£¡£¡£¡£¡£
É豸½«ÔÚ½ÓÏÂÀ´µÄ5ÃëÖÓÄÚ³ÁÆô£¬£¬£¬£¬£¬£¬£¬ËùÓеÄLED¶¼½«ÏñÊ¥µ®Ê÷Ò»ÑùÉÁ¶¯¡£¡£¡£¡£¡£
5. ƾ֤ÐÅϢй©ºÍÃ÷ÎÄÆ¾Ö¤£¨HTTP£©
¹¥»÷ÕßÄܹ»´ÓWAN½Ó¿ÚºÍFTTH LAN½Ó¿Ú½Ó¼ûweb·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ý»ñÈ¡ÒÔÏÂÎļþÀ´ÌáÈ¡Web£¬£¬£¬£¬£¬£¬£¬Telnetƾ֤ºÍSNMPÉçÇø×Ö·û´®£¨¶Áд£©£º
ʹÓÃcurl£º
6. Èõ¼ÓÃÜËã·¨
´æ´¢ÃÜÂëʹÓÃ×Ô½ç˵¼ÓÃÜËã·¨£¬£¬£¬£¬£¬£¬£¬¸ÃËã·¨½«ÃÜÂëÓëÓ²±àÂëÖµ*j7a(L#yZ98sSd5HfSgGjMj8;Ss;d)(*&^#@$a2s0i3g½øÐÐÒì»ò£¬£¬£¬£¬£¬£¬£¬ÈçÏÂËùʾ£º
7. ÖÎÀí½çÃæ²»°²È«
ĬÈÏÇé¿öÏ£¬£¬£¬£¬£¬£¬£¬Ö»ÄÜʹÓÃHTTP¡¢telnetºÍSNMPÔ¶³ÌÖÎÀíÉ豸£¬£¬£¬£¬£¬£¬£¬²»Ö§³ÖHTTPS»òSSH£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»À¹½ØÒÔÃ÷ÎÄ´ó¾Ö·¢Ë͵ÄÃÜÂ룬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýÖÐÑëÈ˹¥»÷£¨MITM£©À´½Ù³ÖÉ豸¡£¡£¡£¡£¡£
0x02 ÓйØÐÂÎÅ
https://seclists.org/fulldisclosure/2020/Jul/7
0x03 ²Î¿¼Á´½Ó
https://pierrekim.github.io/advisories/2020-cdata-0x00-olt.txt
https://pierrekim.github.io/blog/2020-07-07-cdata-olt-0day-vulnerabilities.html
http://pierrekim.github.io/blog/2016-11-01-gpon-ftth-networks-insecurity.html
0x04 ¹¦·òÏß
2020-07-08 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ