TP-Link WR940NºÍWR941ND»º³åÇø·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-04-10

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


TP-Link WR940NºÍWR941ND·ÓÉÆ÷


·ì϶¸ÅÊö


TP-Link WR940NºÍWR941NDÊÇÖйúÆÕÁª£¨TP-LINK£©¹«Ë¾µÄ·ÓÉÆ÷²úÆ·¡£ÆäÖеĻº³åÇøÒç¶Âí½ÅÄܹ»ÔÊÐíÔ¶³Ì¹¥»÷Õß½ÚÔì¡£

ƾ¾ÝTP-Link¹ØÓÚ·ÓÉÆ÷µÄÎĵµ£¬Á½ÖÖÐͺŶ¼ÒÑÍ£²ú¡£È»¶ø£¬ÔÚÏßËÑË÷ÏÔʾÁ½ÖÖÐͺŶ¼Äܹ»´ÓTargetºÍWalmartµÈÁãÊÛÉÌÄÇÀï»ñµÃ¡£


·ì϶ÑéÖ¤


µ±Óû§·¢ËÍpingÒªÇóʱ£¬É豸½ÚÔį̀ÉÏ»áÏÔʾһÌõÐÂÎÅ£¬Ö¸µÄÊDZàÒëΪ¹Ì¼þ¶þ½øÔìÎļþµÄ±¾»ú´úÂë¡£PingÒªÇóÔÚ·ÓÉÆ÷µÄ½ÚÔį̀ÉÏŲÓÃÐÂÎÅÈçÏ£º
 GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͨ¹ýÔËÐÐBurp Suite´úÀíÀ´²é³­ping·þÎñµÄ´«³öGETÒªÇó¡£±ÉÈËͼÖУ¬Äܹ»¿´µ½ÒªÇóµÄ²ÎÊý¡£Ò»ÑùµÄ²ÎÊýÒ²³Ê´Ë¿ÌÉÏͼËùʾµÄ½ÚÔį̀ÐÂÎÅÖС£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ñ¡Ôñͨ¹ý300×Ö½ÚµÄA·¢ËÍ£¬¶øºó¿´¿´»á²úÉúʲô¡£ÔÚʹÓÃBurpÌ×¼þÊ·ýÀ¹½ØHTTPÒªÇóºóÅú¸ÄÁËHTTPÒªÇóÖеÄping_addr²ÎÊý¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͨ¹ý½ÚÔį̀ÉϵÄÒÔÏÂÐÂÎÅÄܹ»¿´µ½£¬ÏÖʵÉÏ£¬Äܹ»¸²¸Ç·µ»ØµØÖ·$ ra²¢ÆðÍ·½ÚÔ취ʽִÐС£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½¨¸´½¨Òé


TP-LinkµÄ°²È«ÍŶӰ䲼ÁËÒ»¸ö²¹¶¡£¬²¢Ö¸³öÕâЩӲ¼þ°æ±¾ÖеÄÁ½¸öÉ豸¶¼²»ÔÙ³ö²ú£¨²úÆ·ÊÙÃüʵÏÖ£©¡£


й̼þÒÑÔÚÍøÕ¾Éϰ䲼£¬ÓÃÓÚÊÜÓ°ÏìµÄÓ²¼þ°æ±¾ÖеÄÁ½¸öÉ豸£¨¹Ì¼þÏóÕ÷Ϊ190218£©¡£ÏÂÔØÒ³ÃæÁ´½Ó
TL-WR940Nv3£ºhttps£º//www.tp-link.com/pl/download/TL-WR940N_V3.html#Firmware
TL-WR941NDv6£ºhttps£º//www.tp-link.com/pl/download/TL-WR941ND.html#Firmware


²Î¿¼Á´½Ó


https://securityintelligence.com/buffer-overflow-vulnerability-in-tp-link-routers-can-allow-remote-attackers-to-take-control/