Vulnerabilities in Realtek SDK have led to issues in devices from 65 manufacturers.

The components of Realtek SDK, used by various manufacturers of wireless devices in their firmware, have revealed four vulnerabilities that allow an unauthenticated attacker to remotely execute code on devices with elevated privileges. Preliminary estimates indicate that the issues affect at least 200 device models from 65 different suppliers, including various models of wireless routers from Asus, A-Link, Beeline, Belkin, Buffalo, D-Link, Edison, Huawei, LG, Logitec, MT-Link, Netgear, Realtek, Smartlink, UPVEL, ZTE, and Zyxel.

The issue affects various classes of wireless devices based on the SoC RTL8xxx, ranging from wireless routers and Wi-Fi extenders to IP cameras and smart lighting control devices. Devices with RTL8xxx chips utilize an architecture that implies the installation of two SoCs — the first hosts the manufacturer's Linux-based firmware, while the second runs a separate stripped-down Linux environment implementing access point functions. The internals of the second environment are based on standard components provided by Realtek in the SDK. These components also process data resulting from external requests.

The vulnerabilities affect products using Realtek SDK v2.x, Realtek 'Jungle' SDK v3.0-3.4, and Realtek 'Luna' SDK up to version 1.3.2. A fix has already been released in the Realtek 'Luna' SDK 1.3.2a update, and patches for the Realtek 'Jungle' SDK are being prepared for publication. No fixes are planned for Realtek SDK 2.x, as support for this branch has already been discontinued. Working exploit prototypes have been provided for all vulnerabilities, allowing the execution of arbitrary code on the device.

The identified vulnerabilities (the first two are assigned a severity level of 8.1, and the others 9.8):

  • CVE-2021-35392 — a buffer overflow in the mini_upnpd and wscd processes, implementing 'WiFi Simple Config' functionality (mini_upnpd handles SSDP packets, while wscd supports both SSDP and services UPnP requests based on the HTTP protocol). An attacker can achieve code execution by sending specially crafted UPnP 'SUBSCRIBE' requests with an oversized port number in the 'Callback' field. SUBSCRIBE /upnp/event/WFAWLANConfig1 HTTP/1.1 Host: 192.168.100.254:52881 Callback: NT: upnp:event
  • CVE-2021-35393 - a vulnerability in the "WiFi Simple Config" handlers, manifesting when using the SSDP protocol (utilizes UDP and a request format similar to HTTP). The issue is caused by the use of a fixed buffer of 512 bytes when processing the "ST:upnp" parameter in M-SEARCH messages sent by clients to detect services in the network.
  • CVE-2021-35394 - a vulnerability in the MP Daemon process responsible for executing diagnostic operations (ping, traceroute). The problem allows for command substitution due to insufficient argument checking when executing external utilities.
  • CVE-2021-35395 - a series of vulnerabilities in web interfaces based on HTTP servers /bin/webs and /bin/boa. In both cases, typical vulnerabilities were identified due to the lack of argument validation before executing external utilities using the system() function. servers Common vulnerabilities were identified due to the lack of argument validation before executing external utilities with the system() function. The differences are limited to using different APIs for the attack. Both handlers lacked protection against CSRF attacks and techniques like "DNS rebinding," which allow sending requests from an external network when access to the interface is restricted to an internal network. The processes also, by default, used a predefined supervisor/supervisor account. Additionally, the handlers revealed several stack overflow issues occurring when arguments of excessive size were sent. POST /goform/formWsc HTTP/1.1 Host: 192.168.100.254 Content-Length: 129 Content-Type: application/x-www-form-urlencoded submit-url=wlwps.asp&resetUnCfg=0&peerPin=12345678;ifconfig>/tmp/1;&setPIN=Start+PIN&configVxd=off&resetRptUnCfg=0&peerRptPin=
  • Additionally, several more vulnerabilities have been discovered in the UDPServer process. It turns out one of the problems was already found by other researchers back in 2015, but it was not fully fixed. The issue is caused by a lack of proper argument checking passed to the system() function and can be exploited by sending a string of the form ‘orf;ls’ to network port 9034. Furthermore, a buffer overflow was identified in UDPServer due to the unsafe use of the sprintf function, which could also potentially be used for attacks.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster