CDATA OLTsÖжà¸ö0day·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-07-08


0x00 ·ì϶¼ò½é


2020Äê7ÔÂ7ÈÕ,×êÑÐÈËÔ±PierreÅû¶ÁËCDATA OLTÖдæÔڵĶà¸ö0day·ì϶£¬£¬£¬£¬ £¬£¬£¬¶Ô²úÆ·µÄ¶à¸ö°æ±¾¶¼ÓÐÓ°Ïì¡£¡£ ¡£¡£¡£×êÑÐÈËÔ±ÒÔΪÕâЩºóÃÅÓ¦ÊÇCDATAÓÐÒ⿪·¢µÄ£¬£¬£¬£¬ £¬£¬£¬Òò¶øÅû¶·ì϶µÄÈ«Êýϸ½Ú£¬£¬£¬£¬ £¬£¬£¬ÕâЩ·ì϶µÄCVEÔÝδ·ÖÅä¡£¡£ ¡£¡£¡£

CDATA OLTÊÇOEM FTTH OLT£¬£¬£¬£¬ £¬£¬£¬Éæ¼°Cdata¡¢OptiLink¡¢V-SOL CNºÍBLIYµÈÆ·ÅÆ¡£¡£ ¡£¡£¡£Ò»Ð©É豸֧³Ö¶à¸ö10 GbÉÏÐÐÁ´Â·£¬£¬£¬£¬ £¬£¬£¬²¢Ìṩ¶à´ï1024¸öONT£¨¿Í»§¶Ë£©µÄInternetÏνӡ£¡£ ¡£¡£¡£

FTTH£¨Fiber To The Home£©£¬£¬£¬£¬ £¬£¬£¬¼´¹âÏ˵½»§ÊÇÖ¸½«¹âÍøÂçµ¥Ôª£¨ONU£©×°ÖÃÔÚס¼ÒÓû§»òÆóÒµÓû§´¦£¬£¬£¬£¬ £¬£¬£¬Êǹâ½ÓÈëϵÁÐÖÐ×î¿¿½üÓû§µÄ¹â½ÓÈëÍøÀûÓÃÀàÐÍ¡£¡£ ¡£¡£¡£FTTHµÄ¹âÏ˽ÓÈë¼¼ÊõÓкöàÖÖ£¬£¬£¬£¬ £¬£¬£¬ÆäÖÐÒ»ÖÖÊÇGPON¡£¡£ ¡£¡£¡£GPON FTTH¼«¶ÈÊ¢ÐУ¬£¬£¬£¬ £¬£¬£¬ÓÉÓÚËü¼ÛÖµ±ãÒË£¬£¬£¬£¬ £¬£¬£¬²¢ÇÒÔÊÐíÈËÃǼ±¾çÏÂÔØºÏ·¨µÄÊÓÆµµã²¥¡£¡£ ¡£¡£¡£

×êÑÐÈËԱʹÓÃ×îй̼þ°æ±¾£¨V1.2.2ºÍ2.4.05_000¡¢2.4.04_001ºÍ2.4.03_000£©ÔÚ³¢ÊÔÊÒ»·¾³ÖÐÑéÖ¤ÁËÕë¶ÔFD1104BºÍFD1108SN OLTµÄ·ì϶¡£¡£ ¡£¡£¡£

ͨ¹ý¾²Ì¬·ÖÎö£¬£¬£¬£¬ £¬£¬£¬ÕâЩ·ìÏ¶ËÆºõÒ²»áÓ°ÏìËùÓпÉÓõÄOLTÄ£ÐÍ£¬£¬£¬£¬ £¬£¬£¬ÓÉÓÚ´úÂë¿âÀàËÆ£º

? 72408A

? 9008A

? 9016A

? 92408A

? 92416A

? 9288

? 97016

? 97024P

? 97028P

? 97042P

? 97084P

? 97168P

? FD1002S

? FD1104

? FD1104B

? FD1104S

? FD1104SN

? FD1108S

? FD1204S-R2

? FD1204SN

? FD1204SN-R2

? FD1208S-R2

? FD1216S-R1

? FD1608GS

? FD1608SN

? FD1616GS

? FD1616SN

? FD8000

´Ó·ÖÎöµÄ¶þ½øÔìÎļþÖУ¬£¬£¬£¬ £¬£¬£¬ÎÒÃÇÌáÈ¡ÁËÓйØOEM´úÀíÉ̵ÄÐÅÏ¢£º

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


´ÓͼÖÐÄܹ»¿´µ½£¬£¬£¬£¬ £¬£¬£¬¸Ã´úÀíÉÌΪÎ÷µÏÌØ£¨CDATA£©£¬£¬£¬£¬ £¬£¬£¬Àö½­ÊÐÎ÷µÏÌØ¿Æ¼¼ÓÐÏÞ¹«Ë¾ÊÇÒ»¼ÒרһÓÚÌṩ¿í´øÍøÂç½ÓÈëÉ豸µÄ¸ß¿Æ¼¼ÆóÒµ¡£¡£ ¡£¡£¡£¹«Ë¾µÄÖØÒª²úÆ·Ô̺¬GPON¡¢EPONÍøÂçÉ豸¡¢EOCÍøÂçÉ豸¡¢CATV¹â´«ÊäÉ豸¡£¡£ ¡£¡£¡£


0x01 ·ì϶ÏêÇé


Õâ´Î·¢Ïֵķì϶Ô̺¬telnetºóÃÅ¡¢Æ¾Ö¤ÐÅϢй©ºÍÃ÷ÎÄÌåʽƾ֤£¨telnet£©¡¢ÓµÓÐrootÌØÈ¨µÄEscape Shell¡¢Ô¤Éí·ÝÑéÖ¤Ô¶³ÌDoS¡¢Æ¾Ö¤ÐÅϢй©ºÍÃ÷ÎÄÆ¾Ö¤£¨HTTP£©¡¢Èõ¼ÓÃÜËã·¨ºÍÖÎÀí½çÃæ²»°²È«£¬£¬£¬£¬ £¬£¬£¬ÏÂÃæ½øÐоßÌå½éÉÜ¡£¡£ ¡£¡£¡£

1. telnetºóÃÅ

¹¥»÷ÕßÄܹ»´ÓWAN½Ó¿ÚºÍFTTH LAN½Ó¿Ú½Ó¼ûtelnet·þÎñ£¬£¬£¬£¬ £¬£¬£¬»ñµÃÖÎÀíÔ±CLI½Ó¼ûȨÏÞ¡£¡£ ¡£¡£¡£·ÖÆçµÄ¹Ì¼þÓÐ·ÖÆçµÄÓ²±àÂëºóÃÅÆ¾Ö¤£¬£¬£¬£¬ £¬£¬£¬²Î¿¼ÈçÏ£º

ÒÔǰµÄ°æ±¾Äܹ»Í¨¹ýÒÔÏ·½Ê½µÇ¼£º

login: suma123¡£¡£ ¡£¡£¡£

password: panger123

×îеÄа汾Äܹ»Í¨¹ýÒÔÏ·½Ê½µÇ¼£º

login: debug

password: debug124

login: root

password: root126

login: guest

password: [empty]


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



ƾ֤ÒÑ´Óоɹ̼þÓ³ÏñÖÐÌáÈ¡¡£¡£ ¡£¡£¡£

ƾ¾Ý·ÖÆçµÄ¹©¸øÉ̺͹̼þ°æ±¾£¬£¬£¬£¬ £¬£¬£¬CLIµÄ±í¹Û¿ÉÄÜÓÐËù·ÖÆç£¬£¬£¬£¬ £¬£¬£¬µ«½Ó¼ûÒÀÈ»ÓÐЧ¡£¡£ ¡£¡£¡£

ʹÓÃsuma123/panger123£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



ʹÓÃguest/[empty]£º

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ʹÓÃroot/root126£º

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ʹÓÃdebug/debug124£º

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



ÓÐÁËÕâЩ½Ó¼ûȨÏÞ£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õß¾ÍÄܹ»¶Ô²úÆ·½øÐÐÅäÖᣡ£ ¡£¡£¡£

2. ƾ֤ÐÅϢй©ºÍÃ÷ÎÄÌåʽƾ֤£¨telnet£©

ÎÒÃÇÈç¹û¹¥»÷ÕßÒѾ­ÓµÓÐCLI½Ó¼ûȨÏÞ£¨Äܹ»Í¨¹ýʹÓÃtelnetµÄBackdoor½Ó¼ûÀ´ÊµÏÖ£©¡£¡£ ¡£¡£¡£

¹¥»÷Õß¿ÉÔÚCLIÖÐÔËÐкÅÁî»ñÈ¡ÖÎÀíԱʹ´¦£º

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


3. ÓµÓÐrootÌØÈ¨µÄEscape Shell

ÎÒÃÇÈç¹û¹¥»÷ÕßÓµÓÐCLI½Ó¼ûȨÏÞ£¨Äܹ»Í¨¹ýʹÓÃtelnetµÄBackdoor½Ó¼ûÀ´ÊµÏÖ£©¡£¡£ ¡£¡£¡£

CLIÖÐÓкÅÁî×¢ÈëÖ°ÄÜ£¬£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßÄܹ»ÒÔrootȨÏÞÖ´ÐкÅÁî¡£¡£ ¡£¡£¡£

ºÅÁî×¢ÈëλÓÚTFTPÏÂÔØÅäÖò¿ÃÅ¡£¡£ ¡£¡£¡£

ÎÒÃÇʹÓÃmetasploitÔÚ192.168.1.101ÉÏÆô¶¯TFTP·þÎñÆ÷£¬£¬£¬£¬ £¬£¬£¬²¢½Ó¹Ü×¢ÈëºÅÁ£¬£¬£¬ £¬£¬£¬Á˾ÖÈçÏ£º

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÔÚOLTÉÏ£º

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÔÚ¹¥»÷ÕßÍÆËã»úÉÏÔËÐеÄTFTP·þÎñÆ÷ÉÏ£¬£¬£¬£¬ £¬£¬£¬ÎÒÃÇÊÕµ½ºÅÁîµÄÊä³öcat /proc/cpuinfo£º

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ò²Äܹ»ÀûÓÃǶÈëʽWeb·þÎñÆ÷À´Ð¹Â¶ÐÅÏ¢£º

ÔÚOLTÉÏ£º

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



ÔÚ¹¥»÷Õß»úеÉÏ£º

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


´Ë±í£¬£¬£¬£¬ £¬£¬£¬»¹ÓкöàºÅÁî¶¼Äܹ»ÒÔrootȨÏÞÖ´ÐУ¬£¬£¬£¬ £¬£¬£¬¾ßÌåÈçÏ£º

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



4. Ô¤Éí·ÝÑéÖ¤Ô¶³ÌDoS

¹¥»÷ÕßÄܹ»´ÓWAN½Ó¿ÚºÍFTTH LAN½Ó¿Ú½Ó¼ûtelnet·þÎñ£¬£¬£¬£¬ £¬£¬£¬Ê¹ÓûùÓÚIA¡¢»úе½ø½¨ºÍshawarmaµÄÍÌͼ¼Êõ£¬£¬£¬£¬ £¬£¬£¬³ÁÆôËùÓÐOLT¡£¡£ ¡£¡£¡£

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


É豸½«ÔÚ½ÓÏÂÀ´µÄ5ÃëÖÓÄÚ³ÁÆô£¬£¬£¬£¬ £¬£¬£¬ËùÓеÄLED¶¼½«ÏñÊ¥µ®Ê÷Ò»ÑùÉÁ¶¯¡£¡£ ¡£¡£¡£

5. ƾ֤ÐÅϢй©ºÍÃ÷ÎÄÆ¾Ö¤£¨HTTP£©

¹¥»÷ÕßÄܹ»´ÓWAN½Ó¿ÚºÍFTTH LAN½Ó¿Ú½Ó¼ûweb·þÎñÆ÷£¬£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ý»ñÈ¡ÒÔÏÂÎļþÀ´ÌáÈ¡Web£¬£¬£¬£¬ £¬£¬£¬Telnetƾ֤ºÍSNMPÉçÇø×Ö·û´®£¨¶Áд£©£º

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ʹÓÃcurl£º

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


6. Èõ¼ÓÃÜËã·¨

´æ´¢ÃÜÂëʹÓÃ×Ô½ç˵¼ÓÃÜËã·¨£¬£¬£¬£¬ £¬£¬£¬¸ÃËã·¨½«ÃÜÂëÓëÓ²±àÂëÖµ*j7a(L#yZ98sSd5HfSgGjMj8;Ss;d)(*&^#@$a2s0i3g½øÐÐÒì»ò£¬£¬£¬£¬ £¬£¬£¬ÈçÏÂËùʾ£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



7. ÖÎÀí½çÃæ²»°²È«

ĬÈÏÇé¿öÏ£¬£¬£¬£¬ £¬£¬£¬Ö»ÄÜʹÓÃHTTP¡¢telnetºÍSNMPÔ¶³ÌÖÎÀíÉ豸£¬£¬£¬£¬ £¬£¬£¬²»Ö§³ÖHTTPS»òSSH£¬£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßÄܹ»À¹½ØÒÔÃ÷ÎÄ´ó¾Ö·¢Ë͵ÄÃÜÂ룬£¬£¬£¬ £¬£¬£¬²¢Í¨¹ýÖÐÑëÈ˹¥»÷£¨MITM£©À´½Ù³ÖÉ豸¡£¡£ ¡£¡£¡£


0x02 ÓйØÐÂÎÅ


https://seclists.org/fulldisclosure/2020/Jul/7


0x03 ²Î¿¼Á´½Ó


https://pierrekim.github.io/advisories/2020-cdata-0x00-olt.txt

https://pierrekim.github.io/blog/2020-07-07-cdata-olt-0day-vulnerabilities.html

http://pierrekim.github.io/blog/2016-11-01-gpon-ftth-networks-insecurity.html


0x04 ¹¦·òÏß


2020-07-08 VSRC°ä²¼·ì϶¹«¸æ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website