¡¾·ì϶¹«¸æ¡¿D-Link DIR-3040·ÓÉÆ÷¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-07-190x00 ·ì϶¸ÅÊö
2021Äê7ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Cisco Talos µÄ×êÑÐÈËÔ±¹«¿ªÅû¶ÁËD-Link DIR-3040·ÓÉÆ÷ÖеĶà¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶ÔÚÊÜÓ°ÏìµÄ·ÓÉÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë¡¢½Ó¼ûÃô¸ÐÐÅÏ¢»òµ¼ÖÂÉ豸±ÀÀ£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°ÕâЩ·ì϶µÄPoCÒѾ¹«¿ª¡£¡£¡£¡£¡£¡£¡£
0x01 ·ì϶ÏêÇé

DIR-3040 ÊÇ»ùÓÚ AC3000 µÄÎÞÏß»¥ÁªÍøÂ·ÓÉÆ÷¡£¡£¡£¡£¡£¡£¡£Cisco Talos±¾´ÎÅû¶µÄ·ì϶Ô̺¬£º
l CVE-2021-21816 £ºSyslog ÐÅϢй¶·ì϶£¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ6.5¡£¡£¡£¡£¡£¡£¡£
l CVE-2021-21817 £ºZebra IP ·ÓÉÖÎÀíÆ÷ÐÅϢй¶·ì϶£¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ7.5¡£¡£¡£¡£¡£¡£¡£
l CVE-2021-21818 £ºZebra IP ·ÓÉÖÎÀíÆ÷Ó²±àÂëÃÜÂë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ7.5¡£¡£¡£¡£¡£¡£¡£
l CVE-2021-21819 £ºLibcli ºÅÁî×¢Èë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.1¡£¡£¡£¡£¡£¡£¡£
l CVE-2021-21820 £ºLibcli ²âÊÔ»·¾³Ó²±àÂëÃÜÂë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ10.0¡£¡£¡£¡£¡£¡£¡£
ÆäÖУ¬£¬£¬£¬£¬£¬£¬£¬CVE-2021-21816ºÍCVE-2021-21817ΪÐÅϢй¶·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ý¶ñÒâÍøÂçÒªÇó´¥·¢£¬£¬£¬£¬£¬£¬£¬£¬³É¹¦ÀûÓÃÄܹ»²é¿´É豸µÄϵͳÈÕÖ¾£»£»£»£»£»£»CVE-2021-21819·ì϶¿ÉÄܵ¼ÖÂËÁÒâºÅÁîÖ´ÐУ¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËÍһϵÁÐÒªÇóÀ´´¥·¢´Ë·ì϶¡£¡£¡£¡£¡£¡£¡£
CVE-2021-21818ºÍCVE-2021-21820¶¼ÎªÓ²±àÂëÃÜÂë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬µ«Ó°Ïì·ÖÆç£¬£¬£¬£¬£¬£¬£¬£¬Ç°Õß¿ÉÄܵ¼Ö»ؾø·þÎñ£¬£¬£¬£¬£¬£¬£¬£¬ºóÕß¿ÉÄܵ¼Ö¹¥»÷ÕßÔÚ·ÓÉÆ÷ÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£
½ØÖ¹Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýZoomEeyËÑË÷£¬£¬£¬£¬£¬£¬£¬£¬È«ÇòÁìÓòÄÚ¹²ËÑË÷µ½20911305¸öD-Link DIR-3040ÓйصÄÉ豸£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÖйúλÁеÚÒ»£¬£¬£¬£¬£¬£¬£¬£¬¹úÄÚÉ¢²¼×î¶àµÄΪ¸£½¨Ê¡¡£¡£¡£¡£¡£¡£¡£

Ó°ÏìÁìÓò
D-Link DIR-3040 ¹Ì¼þ <= v1.13B03
0x02 ´ëÖý¨Òé
ĿǰÕâЩ·ì϶ÒѾ½¨¸´£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéʵʱÀûÓÃD-Link DIR-3040 v1.13B03 ²¹¶¡¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://support.dlink.com/resource/SECURITY_ADVISEMENTS/DIR-3040/REVA/DIR-3040_REVA_FIRMWARE_v1.13B03_HOTFIX.zip
0x03 ²Î¿¼Á´½Ó
https://blog.talosintelligence.com/2021/07/vuln-spotlight-d-link.html
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10228
https://www.bleepingcomputer.com/news/security/d-link-issues-hotfix-for-hard-coded-password-router-vulnerabilities/
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2021-07-19 | ³õ´Î°ä²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ8827Ì«Ñô¼¯ÍÅ
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬£¬£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ