Remote Code Execution Dambudziko muNetgear Routers

Kusagadzikana kwaonekwa muNetgear zvishandiso zvinokutendera kuti uite kodhi yako nemidzi yekodzero pasina humbowo kuburikidza nekunyengedza mune yekunze network padivi peWAN interface. Kusagadzikana kwakasimbiswa muR6900P, R7000P, R7960P uye R8000P isina waya ma routers, pamwe neiyo MR60 uye MS60 mesh network zvishandiso. Netgear yakatoburitsa firmware update inogadzirisa kusagadzikana.

Kusagadzikana uku kunokonzerwa nekuwanda kwemastaki ekumashure maitiro aws_json (/tmp/media/nand/router-analytics/aws_json) kana uchibvisa data muJSON fomati yakagamuchirwa mushure mekutumira chikumbiro kune yekunze webhu sevhisi (https://devicelocation. ngxcld.com/device -location/resolve) inoshandiswa kuona nzvimbo yemudziyo. Kuti uite kurwisa, unofanirwa kuisa faira yakanyatsogadzirwa muJSON fomati pane yako webhu server uye kumanikidza router kurodha iyi faira, semuenzaniso, kuburikidza neDNS spoofing kana kuendesa zvakare chikumbiro kune inofambiswa node (iwe unofanirwa kubata a chikumbiro kune iyo host devicelocation.ngxcld.com yakaitwa pakatanga mudziyo ). Chikumbiro chinotumirwa pamusoro peHTTPS protocol, asi pasina kutarisa chokwadi chechitupa (kana uchirodha, shandisa curl utility ne "-k" sarudzo).

Padivi rinoshanda, kusazvibata kunogona kushandiswa kukanganisa mudziyo, semuenzaniso, nekuisa yekumashure kune inotevera kutonga pamusoro petiweki yemukati yebhizinesi. Kuti urwise, zvinodikanwa kuti uwane nguva pfupi yekuwana iyo Netgear router kana kune network tambo / midziyo padivi reWAN interface (semuenzaniso, kurwiswa kunogona kuitwa neISP kana munhu anorwisa akawana mukana kune iyo kutaurirana nhoo). Sekuratidzira, vaongorori vakagadzirira prototype kurwisa mudziyo wakavakirwa paRaspberry Pi bhodhi, iyo inobvumira munhu kuwana midzi ganda kana achibatanidza iyo WAN interface yeanotambura router kune bhodhi reEthernet port.

Source: opennet.ru

Voeg