»ªË¶Â·ÓÉÆ÷¿çÕ¾¾ç±¾¹¥»÷·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-10-26·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2018-18287£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
¸Ã·ì϶ӰÏìÁË»ªË¶RT-AC58U v3.0.0.4.380_6516·ÓÉÆ÷¡£
·ì϶¸ÅÊö
°²È«×êÑÐÈËÔ±·¢ÏÖ£¬ÔÚ»ªË¶RT-AC58U·ÓÉÆ÷ÖдæÔÚ¿çÕ¾¾ç±¾¹¥»÷·ì϶¡£·ÖÎöÅú×¢£¬¸Ã·ì϶ÔÊÐíÔ¶³Ì¹¥»÷ÕßÏòÉ豸עÈëËÁÒâWeb»òHTML¾ç±¾£¬µ¼ÖÂLogout.asp, Main_Login.asp, apply.cgi, clients.asp, disk.asp, disk_utility.asp, or internet.aspµÈÒ³Ãæ¾ùÊܵ½Ó°Ïì¡£
¹úÄÚ¶³öÔÚ»¥ÁªÍøµÄ¸Ã·ì϶ÓйØÍøÂç×ʲúÉ¢²¼Í¼
·ì϶ÑéÖ¤
https://github.com/remix30303/AsusLeak
½¨¸´½¨Òé
»¹Î´°ä²¼Óйطì϶µÄ²¹¶¡£¬Çë¹Ø×¢¹ÙÍø¸üУºhttps://www.asus.com/Microsite/2015/networks/routerfirmware_update/
´Ë±í£¬½¨ÒéÓйØÓû§Ó¦²ÉÈ¡µÄÆäËû°²È«·À»¤´ëÊ©ÈçÏ£º
£¨1£©×î´óÏ޶ȵØÏ÷¼õËùÓнÚÔìϵͳÉ豸ºÍ/»òϵͳµÄÍøÂç¶³ö£¬²¢È·±£ÎÞ·¨´ÓInternet½Ó¼û¡£
£¨2£©¶¨Î»·À»ðǽ·À»¤µÄ½ÚÔìÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸£¬²¢½«ÆäÓëÒµÎñÍøÂç¸ôÀë¡£
£¨3£©µ±±ØÒªÔ¶³Ì½Ó¼ûʱ£¬ÇëʹÓð²È«²½ÖèÈçÐ鹹רÓÃÍøÂ磨VPN£©£¬ÒªÒâʶµ½VPN¿ÉÄÜ´æÔڵķì϶£¬Ð轫VPN¸üе½×îа汾¡£
²Î¿¼Á´½Ó
https://nvd.nist.gov/vuln/detail/CVE-2018-18287#


¾©¹«Íø°²±¸11010802024551ºÅ