D-Link DNS-320É豸Զ³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-09-24

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-16057£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


D-Link DNS-320 2.05.B10¼°Ö®Ç°°æ±¾


·ì϶¸ÅÊö


D-Link DNS-320ÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îNAS£¨ÍøÂç´ÓÊô´æ´¢£©É豸¡£


×êÑÐÈËÔ±·¢ÏÖD-Link DNS-320 ShareCenterÉ豸´æÔÚÒ»¸öºÅÁî×¢Èë·ì϶£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶Զ³Ì½ÚÔìÉ豸²¢½Ó¼ûÉ豸ÉÏ´æ´¢µÄÎļþ¡£


ƾ¾Ý×êÑÐÈËÔ±µÄ»ã±¨£¬¸Ã·ì϶ÓëDNS-320ÖÎÀí½çÃæµÄSSL LoginµÄ°µ²ØÖ°ÄÜÓйØ£¬ÊÜÓ°ÏìµÄÄ£¿é/cgi/login_mgr.cgiÔ̺¬Ò»¸ö¿ÉÄܱ»ÀûÓõIJÎÊýport£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚrootȨÏÞÏÂÖ´ÐÐËÁÒâºÅÁ´Ó¶øµ¼ÖÂÉ豸±»ÊÕÊÜ¡£ 

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


·ì϶ÑéÖ¤

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬¼û²Î¿¼Á´½Ó¡£


²Î¿¼Á´½Ó


https://blog.cystack.net/d-link-dns-320-rce/