TP-Link½¨¸´Archer·ÓÉÆ÷Éí·ÝÑéÖ¤ÈÆ¹ý·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2019-12-17·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-7405£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8
Ó°Ïì°æ±¾
Archer C5 V4¡¢Archer MR200v4¡¢Archer MR6400v4ºÍArcher MR400v3·ÓÉÆ÷
·ì϶¸ÅÊö
TP-Link½¨¸´²¿ÃÅArcher·ÓÉÆ÷Öеݲȫ·ì϶£¬¸Ã·ì϶ʹµÃ¹¥»÷ÕßÄܹ»ÎÞÐèÖÎÀíÔ±ÃÜÂë¼´¿ÉÊÕÊÜÉ豸¡£¹¥»÷Õß¿Éͨ¹ý·¢ËÍ×Ö·û´®³¤¶È³¬¹ýÔÊÐíµÄ×Ö½ÚÊýµÄHTTPÒªÇó£¬Ê¹µÃÓû§ÃÜÂë±»´úÌæÎª¿ÕÖµ£¬´Ó¶ø»ñµÃ·ÓÉÆ÷µÄadminȨÏÞ¡£¸Ã¹¥»÷»¹»áʹºÏ·¨Óû§±»Ëø¶¨£¬²¢ÇÒÎÞ·¨Í¨¹ýÓû§½çÃæµÇ¼Web·þÎñ£¨ÃÜÂë±»Çå¿Õ¶øÓû§²¢²»ÖªÇ飩¡£
Ö»¹Ü´æÔÚÄÚÖÃÑéÖ¤£¬µ«Á˾ÖÒÀÈ»Èç´Ë£¬ÓÉÓÚÄÚÖÃÑéÖ¤½ö»á²é³ÒýÓÃµÄ HTTP ±êÍ·£¬µ¼Ö¹¥»÷Õßͨ¹ýʹÓÃÓ²±àÂëµÄ tplinkwifi.netÖµÓÕÆÂ·ÓÉÆ÷µÄ httpd ·þÎñÒÔΪҪÇóÊǺϷ¨µÄ¡£
ÈçÏÂͼ£¬½öʹÓá° admin¡±×÷ΪÓû§Ãû¼´¿É½Ó¼ûTELNETºÍFTP£¬¶øÎÞÐèÊäÈëÈκÎÃÜÂ룬ĬÈÏÇé¿öÏ£¬¸ÃÓû§ÃûÊÇÉ豸ÉÏΨһ¿ÉÓõÄÓû§¡£
·ì϶ÑéÖ¤
POC£ºhttps://securityintelligence.com/posts/tp-link-archer-router-vulnerability-voids-admin-password-can-allow-remote-takeover/¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѽ¨¸´·ì϶£¬½¨ÒéÓû§¾¡¿ì×°Öò¹¶¡£º
Archer C5 V4£ºhttps://static.tp-link.com/2019/201909/20190917/Archer_C5v4190815.rar
Archer MR200v4£ºhttps://static.tp-link.com/2019/201909/20190903/Archer%20MR200(EU)_V4_20190730.zip
Archer MR6400v4£ºhttps://static.tp-link.com/2019/201908/20190826/Archer%20MR6400(EU)_V4_20190730.zip
Archer MR400v3£ºhttps://static.tp-link.com/2019/201908/20190826/Archer%20MR400(EU)_V3_20190730.zip
²Î¿¼Á´½Ó
https://securityintelligence.com/posts/tp-link-archer-router-vulnerability-voids-admin-password-can-allow-remote-takeover/


¾©¹«Íø°²±¸11010802024551ºÅ