Vulnerabilitetet në Realtek SDK kanë çuar në probleme në pajisjet e 65 prodhuesve

Në komponentet e Realtek SDK, që përdoret nga ndryshëm prodhues të pajisjeve wireless në firmware e tyre, janë zbuluar katër vulnerabilitete që lejojnë një sulmues pa autentikim të ekzekutojë kod nga larg në pajisje me privilegje të shtuara. Sipas vlerësimeve paraprake, problemet prek të paktën 200 modele pajisjesh nga 65 furnizues të ndryshëm, duke përfshirë modele të ndryshme të routerëve wireless nga Asus, A-Link, Beeline, Belkin, Buffalo, D-Link, Edison, Huawei, LG, Logitec, MT-Link, Netgear, Realtek, Smartlink, UPVEL, ZTE dhe Zyxel.

Problemi përfshin klasa të ndryshme pajisjesh wireless mbi bazën e SoC RTL8xxx, nga routerët wireless dhe amplifikatorët Wi-Fi, deri te kamerat IP dhe pajisjet inteligjente për menaxhimin e ndriçimit. Në pajisjet që përdorin çipat RTL8xxx, përdoret një arkitekturë që parashikon instalimin e dy SoC - në të parin instalohet firmware i prodhuesit mbi bazën e Linux, ndërsa në të dytin ekzekutohet një ambient i veçantë dhe i reduktuar Linux me implementimin e funksioneve të pikës së qasjes. Materialet e ambientit të dytë bazohen në komponentët standard që ofrohen nga kompania Realtek në SDK. Komponentët e përmendur veçanërisht përpunojnë të dhënat që vijnë si pasojë e dërgimit të kërkesave të jashtme.

Vulnerabilitetet ndikojnë produktet që përdorin Realtek SDK v2.x, Realtek 'Jungle' SDK v3.0-3.4 dhe Realtek 'Luna' SDK deri në versionin 1.3.2. Një korrigjim është lëshuar tashmë në azhurnimin e Realtek 'Luna' SDK 1.3.2a, si dhe po përgatiten patches për Realtek 'Jungle' SDK. Për Realtek SDK 2.x, nuk është planifikuar të lëshohen korrigjime, pasi mbështetja për këtë degë tashmë është ndërprerë. Për të gjitha vulnerabilitetet janë ofruar prototipa funksionalë të eksploiteve që mundësojnë ekzekutimin e kodit tuaj në pajisje.

Vulnerabilitetet e zbuluara (dy të parat kanë marrë nivelin e rrezikshmërisë 8.1, ndërsa të tjerat 9.8):

  • CVE-2021-35392 — bufer overflow in the mini_upnpd and wscd processes, which implement the "WiFi Simple Config" functionality (mini_upnpd handles SSDP packet processing, while wscd, in addition to supporting SSDP, services UPnP requests based on the HTTP protocol). An attacker can achieve code execution by sending specially formatted UPnP "SUBSCRIBE" requests with an excessively large port number in the "Callback" field. SUBSCRIBE /upnp/event/WFAWLANConfig1 HTTP/1.1 Host: 192.168.100.254:52881 Callback: NT: upnp:event
  • CVE-2021-35393 — a vulnerability in the "WiFi Simple Config" handlers, occurring when using the SSDP protocol (which uses UDP and a request format similar to HTTP). The issue is caused by the use of a fixed buffer of 512 bytes when processing the "ST:upnp" parameter in M-SEARCH messages sent by clients to discover services on the network.
  • CVE-2021-35394 — a vulnerability in the MP Daemon process responsible for executing diagnostic operations (ping, traceroute). The problem allows the injection of custom commands due to inadequate argument checking when executing external utilities.
  • CVE-2021-35395 — a series of vulnerabilities in the web interfaces based on the http servers /bin/webs and /bin/boa. In both cases, typical vulnerabilities were identified due to the lack of argument validation before executing external utilities using the system() function. The differences are limited to using different APIs for the attack. Both handlers did not include protections against CSRF attacks and "DNS rebinding" techniques, which allow requests from external networks to be sent when access to the interface is restricted to the internal network. Additionally, predefined supervisor/supervisor accounts were used by default in the processes. Furthermore, several stack overflows were identified in the handlers that manifest when arguments of excessive size are sent. POST /goform/formWsc HTTP/1.1 Host: 192.168.100.254 Content-Length: 129 Content-Type: application/x-www-form-urlencoded submit-url=wlwps.asp&resetUnCfg=0&peerPin=12345678;ifconfig>/tmp/1;&setPIN=Start+PIN&configVxd=off&resetRptUnCfg=0&peerRptPin= sistemet u janĂ« identifikuar dobĂ«sitĂ« tipike, tĂ« shkaktuara nga mungesa e verifikimit tĂ« argumenteve pĂ«rpara se tĂ« ekzekutohen mjete tĂ« jashtme nga funksioni system(). Diferencat pĂ«rfshijnĂ« vetĂ«m pĂ«rdorimin e API-ve tĂ« ndryshme pĂ«r sulm. TĂ« dy trajtuesit nuk pĂ«rfshinin mbrojtje ndaj sulmeve CSRF dhe teknikave tĂ« "DNS rebinding", qĂ« lejojnĂ« dĂ«rgimin e kĂ«rkesave nga njĂ« rrjet tĂ« jashtĂ«m duke kufizuar aksesin nĂ« ndĂ«rfaqe vetĂ«m pĂ«r njĂ« rrjet tĂ« brendshĂ«m. Po ashtu, nĂ« procese ishte pĂ«rdorur si llogari parazgjedhur llogaria supervisor/supervisor. PĂ«r mĂ« tepĂ«r, nĂ« trajtuesit janĂ« zbuluar disa mbingopje tĂ« grumbullimit, qĂ« shfaqen kur dĂ«rgohen argumente me madhĂ«si shumĂ« tĂ« madhe. POST /goform/formWsc HTTP/1.1 Host: 192.168.100.254 Content-Length: 129 Content-Type: application/x-www-form-urlencoded submit-url=wlwps.asp&resetUnCfg=0&peerPin=12345678;ifconfig>/tmp/1;&setPIN=Start+PIN&configVxd=off&resetRptUnCfg=0&peerRptPin=
  • Gjithashtu, Ă«shtĂ« vĂ«nĂ« re identifikimi i disa dobĂ«sive tĂ« tjera nĂ« procesin UDPServer. Siç duket, njĂ« nga problemet ishte zbuluar nga studiues tĂ« tjerĂ« qĂ« nĂ« vitin 2015, por nuk ishte rregulluar plotĂ«sisht. Problemi shkaktohet nga mungesa e kontrollit tĂ« duhur tĂ« argumenteve qĂ« i kalohen funksionit system() dhe mund tĂ« shfrytĂ«zohet duke dĂ«rguar nĂ« portin rrjetĂ« 9034 njĂ« varg tĂ« tillĂ« si ‘orf;ls’. PĂ«rveç kĂ«saj, nĂ« UDPServer Ă«shtĂ« identifikuar njĂ« mbushje e tamponit pĂ«r shkak tĂ« pĂ«rdorimit tĂ« pasigurt tĂ« funksionit sprintf, qĂ« gjithashtu mund tĂ« pĂ«rdoret potencialisht pĂ«r tĂ« realizuar sulme.

Burimi: opennet.ru

Blini hosting tĂ« besueshĂ«m pĂ«r faqe interneti me mbrojtje nga DDoS, serverĂ« VPS VDS đŸ”„ Blini hosting tĂ« besueshĂ«m pĂ«r faqe interneti me mbrojtje nga DDoS, serverĂ« VPS VDS | ProHoster