ืคื’ื™ืขื•ื™ื•ืช ื‘- Realtek SDK ื”ื•ื‘ื™ืœื• ืœื‘ืขื™ื•ืช ื‘ืžื›ืฉื™ืจื™ื ืฉืœ 65 ื™ืฆืจื ื™ื

ื–ื•ื”ื• ืืจื‘ืข ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืจื›ื™ื‘ื™ื ืฉืœ Realtek SDK, ื”ืžืฉืžืฉื™ื ื™ืฆืจื ื™ ืžื›ืฉื™ืจื™ื ืืœื—ื•ื˜ื™ื™ื ืฉื•ื ื™ื ื‘ืงื•ืฉื—ื” ืฉืœื”ื, ืฉืขืœื•ืœื•ืช ืœืืคืฉืจ ืœืชื•ืงืฃ ืœื ืžืื•ืžืช ืœื‘ืฆืข ืžืจื—ื•ืง ืงื•ื“ ื‘ืžื›ืฉื™ืจ ืขื ื”ืจืฉืื•ืช ื’ื‘ื•ื”ื•ืช. ืขืœ ืคื™ ื”ืขืจื›ื•ืช ืจืืฉื•ื ื™ื•ืช, ื”ื‘ืขื™ื•ืช ืžืฉืคื™ืขื•ืช ืขืœ ืœืคื—ื•ืช 200 ื“ื’ืžื™ ืžื›ืฉื™ืจื™ื ืž-65 ืกืคืงื™ื ืฉื•ื ื™ื, ื›ื•ืœืœ ื“ื’ืžื™ื ืฉื•ื ื™ื ืฉืœ ื ืชื‘ื™ื ืืœื—ื•ื˜ื™ื™ื Asus, A-Link, Beeline, Belkin, Buffalo, D-Link, Edison, Huawei, LG, Logitec, MT- Link, Netgear, Realtek, Smartlink, UPVEL, ZTE ื•-Zyxel.

ื”ื‘ืขื™ื” ืžื›ืกื” ืกื•ื’ื™ื ืฉื•ื ื™ื ืฉืœ ืžื›ืฉื™ืจื™ื ืืœื—ื•ื˜ื™ื™ื ื”ืžื‘ื•ืกืกื™ื ืขืœ RTL8xxx SoC, ื”ื—ืœ ืžื ืชื‘ื™ื ืืœื—ื•ื˜ื™ื™ื ื•ืžื’ื‘ืจื™ Wi-Fi ื•ืขื“ ืœืžืฆืœืžื•ืช IP ื•ื”ืชืงื ื™ ื‘ืงืจืช ืชืื•ืจื” ื—ื›ืžื™ื. ืžื›ืฉื™ืจื™ื ื”ืžื‘ื•ืกืกื™ื ืขืœ ืฉื‘ื‘ื™ RTL8xxx ืžืฉืชืžืฉื™ื ื‘ืืจื›ื™ื˜ืงื˜ื•ืจื” ื”ื›ื•ืœืœืช ื”ืชืงื ื” ืฉืœ ืฉื ื™ SoCs - ื”ืจืืฉื•ืŸ ืžืชืงื™ืŸ ืืช ื”ืงื•ืฉื—ื” ื”ืžื‘ื•ืกืกืช ืขืœ ืœื™ื ื•ืงืก ืฉืœ ื”ื™ืฆืจืŸ, ื•ื”ืฉื ื™ ืžืจื™ืฅ ืกื‘ื™ื‘ืช ืœื™ื ื•ืงืก ืžื•ืคืฉื˜ืช ื ืคืจื“ืช ืขื ื”ื˜ืžืขืช ืคื•ื ืงืฆื™ื•ืช ืฉืœ ื ืงื•ื“ื•ืช ื’ื™ืฉื”. ื”ืžื™ืœื•ื™ ืฉืœ ื”ืกื‘ื™ื‘ื” ื”ืฉื ื™ื™ื” ืžื‘ื•ืกืก ืขืœ ืจื›ื™ื‘ื™ื ืกื˜ื ื“ืจื˜ื™ื™ื ืฉืžืกื•ืคืงื™ื ืขืœ ื™ื“ื™ Realtek ื‘-SDK. ืจื›ื™ื‘ื™ื ืืœื• ืžืขื‘ื“ื™ื ื’ื ื ืชื•ื ื™ื ื”ืžืชืงื‘ืœื™ื ื›ืชื•ืฆืื” ืžืฉืœื™ื—ืช ื‘ืงืฉื•ืช ื—ื™ืฆื•ื ื™ื•ืช.

ื”ืคื’ื™ืขื•ื™ื•ืช ืžืฉืคื™ืขื•ืช ืขืœ ืžื•ืฆืจื™ื ื”ืžืฉืชืžืฉื™ื ื‘- Realtek SDK v2.x, Realtek "Jungle" SDK v3.0-3.4 ื•- Realtek "Luna" SDK ืœืคื ื™ ื’ืจืกื” 1.3.2. ื”ืชื™ืงื•ืŸ ื›ื‘ืจ ืฉื•ื—ืจืจ ื‘ืขื“ื›ื•ืŸ Realtek "Luna" SDK 1.3.2a, ื•ื’ื ืชื™ืงื•ื ื™ื ืขื‘ื•ืจ Realtek "Jungle" SDK ืžื•ื›ื ื™ื ืœืคืจืกื•ื. ืื™ืŸ ืชื•ื›ื ื™ื•ืช ืœืฉื—ืจืจ ืชื™ืงื•ื ื™ื ื›ืœืฉื”ื ืขื‘ื•ืจ Realtek SDK 2.x, ืžื›ื™ื•ื•ืŸ ืฉื”ืชืžื™ื›ื” ื‘ืกื ื™ืฃ ื–ื” ื›ื‘ืจ ื”ื•ืคืกืงื”. ืขื‘ื•ืจ ื›ืœ ื”ืคื’ื™ืขื•ื™ื•ืช, ืžืกื•ืคืงื™ื ืื‘ื•ืช ื˜ื™ืคื•ืก ืฉืœ ื ื™ืฆื•ืœ ืขื•ื‘ื“ื™ื ื”ืžืืคืฉืจื™ื ืœืš ืœื”ืคืขื™ืœ ืืช ื”ืงื•ื“ ืฉืœืš ื‘ืžื›ืฉื™ืจ.

ืคื’ื™ืขื•ื™ื•ืช ืžื–ื•ื”ื•ืช (ืœืฉืชื™ ื”ืจืืฉื•ื ื•ืช ืžื•ืงืฆื™ืช ืจืžืช ื—ื•ืžืจื” ืฉืœ 8.1, ื•ื”ืฉืืจ - 9.8):

  • CVE-2021-35392 - ื’ืœื™ืฉืช ืžืื’ืจ ื‘ืชื”ืœื™ื›ื™ mini_upnpd ื•-wscd ื”ืžื™ื™ืฉืžื™ื ืืช ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช "WiFi Simple Config" (mini_upnpd ืžืขื‘ื“ ืžื ื•ืช SSDP, ื•-wscd, ื‘ื ื•ืกืฃ ืœืชืžื™ื›ื” ื‘-SSDP, ืžืขื‘ื“ ื‘ืงืฉื•ืช UPnP ืขืœ ื‘ืกื™ืก ืคืจื•ื˜ื•ืงื•ืœ HTTP). ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ืฉื™ื’ ื‘ื™ืฆื•ืข ืฉืœ ื”ืงื•ื“ ืฉืœื• ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื‘ืงืฉื•ืช UPnP "SUBSCRIBE" ื‘ืขืœื•ืช ืžื‘ื ื” ืžื™ื•ื—ื“ ืขื ืžืกืคืจ ื™ืฆื™ืื” ื’ื“ื•ืœ ืžื“ื™ ื‘ืฉื“ื” "Callback". ื”ื™ืจืฉื /upnp/event/WFAWLANConfig1 ืžืืจื— HTTP/1.1: 192.168.100.254:52881 ื”ืชืงืฉืจื•ืช ื—ื•ื–ืจืช: NT:upnp:event
  • CVE-2021-35393 ื”ื™ื ืคื’ื™ืขื•ืช ื‘ืžื˜ืคืœื™ WiFi Simple Config ื”ืžืชืจื—ืฉืช ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืคืจื•ื˜ื•ืงื•ืœ SSDP (ืžืฉืชืžืฉ ื‘-UDP ื•ื‘ืคื•ืจืžื˜ ื‘ืงืฉื” ื”ื“ื•ืžื” ืœ-HTTP). ื”ื‘ืขื™ื” ื ื’ืจืžืช ืขืœ ื™ื“ื™ ืฉื™ืžื•ืฉ ื‘ืžืื’ืจ ืงื‘ื•ืข ืฉืœ 512 ื‘ืชื™ื ื‘ืขืช ืขื™ื‘ื•ื“ ื”ืคืจืžื˜ืจ "ST:upnp" ื‘ื”ื•ื“ืขื•ืช M-SEARCH ืฉื ืฉืœื—ื•ืช ืขืœ ื™ื“ื™ ืœืงื•ื—ื•ืช ื›ื“ื™ ืœืงื‘ื•ืข ืืช ื ื•ื›ื—ื•ืช ื”ืฉื™ืจื•ืชื™ื ื‘ืจืฉืช.
  • CVE-2021-35394 ื”ื™ื ื ืงื•ื“ืช ืชื•ืจืคื” ื‘ืชื”ืœื™ืš MP Daemon, ื”ืื—ืจืื™ืช ืขืœ ื‘ื™ืฆื•ืข ืคืขื•ืœื•ืช ืื‘ื—ื•ืŸ (ืคื™ื ื’, traceroute). ื”ื‘ืขื™ื” ืžืืคืฉืจืช ื”ื—ืœืคื” ืฉืœ ืคืงื•ื“ื•ืช ืžืฉืœื• ืขืงื‘ ื‘ื“ื™ืงื” ืœื ืžืกืคืงืช ืฉืœ ืืจื’ื•ืžื ื˜ื™ื ื‘ืขืช ื‘ื™ืฆื•ืข ื›ืœื™ ืขื–ืจ ื—ื™ืฆื•ื ื™ื™ื.
  • CVE-2021-35395 ื”ื™ื ืกื“ืจื” ืฉืœ ืคื’ื™ืขื•ื™ื•ืช ื‘ืžืžืฉืงื™ ืื™ื ื˜ืจื ื˜ ื”ืžื‘ื•ืกืกื™ื ืขืœ ืฉืจืชื™ http /bin/webs ื•-/bin/boa. ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืื•ืคื™ื™ื ื™ื•ืช ื”ื ื’ืจืžื•ืช ื›ืชื•ืฆืื” ืžื”ื™ืขื“ืจ ื‘ื“ื™ืงืช ืืจื’ื•ืžื ื˜ื™ื ืœืคื ื™ ื”ืฉืงืช ื›ืœื™ ืขื–ืจ ื—ื™ืฆื•ื ื™ื™ื ื‘ืืžืฆืขื•ืช ื”ืคื•ื ืงืฆื™ื” system() ื–ื•ื”ื• ื‘ืฉื ื™ ื”ืฉืจืชื™ื. ื”ื”ื‘ื“ืœื™ื ืžืกืชื›ืžื™ื ืจืง ื‘ืฉื™ืžื•ืฉ ื‘ืžืžืฉืงื™ API ืฉื•ื ื™ื ืœื”ืชืงืคื•ืช. ืฉื ื™ ื”ืžื˜ืคืœื™ื ืœื ื›ืœืœื• ื”ื’ื ื” ืžืคื ื™ ื”ืชืงืคื•ืช CSRF ื•ื˜ื›ื ื™ืงืช "DNS rebinding", ื”ืžืืคืฉืจืช ืฉืœื™ื—ืช ื‘ืงืฉื•ืช ืžืจืฉืช ื—ื™ืฆื•ื ื™ืช ืชื•ืš ื”ื’ื‘ืœืช ื’ื™ืฉื” ืœืžืžืฉืง ืจืง ืœืจืฉืช ื”ืคื ื™ืžื™ืช. ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ ืชื”ืœื™ื›ื™ื ื”ื™ื ื’ื ืœื—ืฉื‘ื•ืŸ ื”ืžืคืงื—/ื”ืžืคืงื— ืฉื”ื•ื’ื“ืจ ืžืจืืฉ. ื‘ื ื•ืกืฃ, ื–ื•ื”ื• ืžืกืคืจ ื”ืฆืคื•ืช ืžื—ืกื ื™ื•ืช ื‘ืžื˜ืคืœื™ื, ื”ืžืชืจื—ืฉื•ืช ื›ืืฉืจ ื ืฉืœื—ื™ื ืืจื’ื•ืžื ื˜ื™ื ื’ื“ื•ืœื™ื ืžื“ื™. POST /goform/formWsc HTTP/1.1 ืžืืจื—: 192.168.100.254 ืื•ืจืš ืชื•ื›ืŸ: 129 ืกื•ื’ ืชื•ื›ืŸ: application/x-www-form-urlencoded submit-url=%2Fwlwps.asp&resetUnCfg=0&peerPin=12345678/1/0 ;&setPIN=ื”ืชื—ืœ+PIN&configVxd=off&resetRptUnCfg=XNUMX&peerRptPin=
  • ื‘ื ื•ืกืฃ, ื–ื•ื”ื• ืขื•ื“ ืžืกืคืจ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืชื”ืœื™ืš UDPServer. ื›ืคื™ ืฉื”ืชื‘ืจืจ, ืื—ืช ื”ื‘ืขื™ื•ืช ื›ื‘ืจ ื”ืชื’ืœืชื” ืขืœ ื™ื“ื™ ื—ื•ืงืจื™ื ืื—ืจื™ื ื‘-2015, ืืš ืœื ืชื•ืงื ื” ืœื—ืœื•ื˜ื™ืŸ. ื”ื‘ืขื™ื” ื ื’ืจืžืช ืžื—ื•ืกืจ ืื™ืžื•ืช ืชืงื™ืŸ ืฉืœ ื”ืืจื’ื•ืžื ื˜ื™ื ืฉื”ื•ืขื‘ืจื• ืœืคื•ื ืงืฆื™ื” system() ื•ื ื™ืชืŸ ืœื ืฆืœ ืื•ืชื” ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ืžื—ืจื•ื–ืช ื›ืžื• 'orf;ls' ืœื™ืฆื™ืืช ืจืฉืช 9034. ื‘ื ื•ืกืฃ, ื–ื•ื”ืชื” ื’ืœื™ืฉืช ื—ื™ืฅ ื‘-UDPServer ืขืงื‘ ืฉื™ืžื•ืฉ ืœื ืžืื•ื‘ื˜ื— ื‘ืคื•ื ืงืฆื™ื™ืช sprintf, ืืฉืจ ืขืฉื•ื™ื” ืœืฉืžืฉ ื’ื ืœื‘ื™ืฆื•ืข ื”ืชืงืคื•ืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”