ÐÅÈñWACºÅÁî×¢Èë·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-05-21·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-9161£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8
Ó°Ïì°æ±¾
ÐÅÈñWAC 3.7.4.2¼°Ö®Ç°°æ±¾
·ì϶¸ÅÊö
Sundray WLAN Controller£¨ÐÅÈñWAC£©ÊÇÖйúÐÅÈñÍø¿Æ¼¼Êõ£¨Sundray£©¹«Ë¾µÄÒ»Ì×ÎÞÏß¾ÖÓòÍø½ÚÔìÆ÷Èí¼þ¡£ÐÅÈñ¿Æ¼¼ÖØÒªÒµÎñΪÆóÒµ¼¶ÎÞÏßÍøÂç¡¢ÎïÁªÍøÒÔ¼°ÖÇÄÜ»¥»»»ú²úÆ·µÄ¿ª·¢¡¢ÀûÓã¬ÐÐÒµ¿Í»§×ÜÁ¿³¬¹ý55000¼Ò¡£¾ÝIDCÊý¾ÝÏÔʾ£¬2018Ä꣬ÐÅÈñÎÞÏßÔÚÖйúÆóÒµ¼¶WLANÊг¡ÅÅÃûµÚÈý¡£
ÎÞÏß½ÚÔìÆ÷Ó²¼þ(AC)´æÔÚÒ»¸öÎÞÐèµÇ¼µÄRCE·ì϶²¢¿Éͨ¹ýWebUIÖ°ÄÜȱµãÖ±½Ó»ñÈ¡É豸µÄroot½ÚÔìȨÏÞ¡£ACÉ豸ÍùÍùÊÇÒ»¸öÆóÒµ°ì¹«ÍøÂçµÄÉÏÍøÈë¿Ú£¬¶Ô½ÓÆóÒµÈÏ֤ϵͳ£¨LDAPµÈ£©£¬²¢¿ÉÄÜÁ¬Í¨¸÷³ö²ú¡¢°ì¹«ÍøÂ磨OA¡¢GitlabµÈ£©¡£Òò¶ø£¬¹¥»÷Õß¿ÉÒÀ´Ë·ì϶»ñÈ¡ÆóÒµÄÚÍøÖÜÓεÄõè¾¶£¬½ø¶ø·¢Õ¹¶ÔÆóÒµÄÚÍøµÄ³ÖÐøÉøÈëºÍ¹¥»÷£¨APT£©¡£
Ô¶³Ì¹¥»÷Õ߿ɽèÖúnginx_webconsole.php°üÍ·ÖеÄshellÔª×Ö·û¶ÁÈ¡´øÓÐadminÃÜÂëµÄetc/config/wac/wns_cfg_admin_detail.xmlÎļþ£¬ÀûÓø÷ì϶»ñȡϵͳµÄÈ«ÊýȨÏÞ¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC¡¢EXP¡£
½¨¸´½¨Òé
http://www.sundray.com.cn
²Î¿¼Á´½Ó
https://nvd.nist.gov/vuln/detail/CVE-2019-9161


¾©¹«Íø°²±¸11010802024551ºÅ