ZyXEL Cloud CNM SecuManagerδÊÚȨԶ³Ì´úÂëÖ´Ðзì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-03-16

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ZyXEL Cloud CNM SecuManager <=3.1.1


·ì϶¸ÅÊö


Zyxel Cloud CNM SecuManagerÊÇÒ»¿îÈ«ÃæµÄÍøÂçÖÎÀíÈí¼þ£¬¿ÉÌṩ¼¯³É½ÚÔį̀À´¼à¶½ºÍÖÎÀí°²È«Íø¹Ø£¬Ô̺¬ZyWALLUSGºÍVPNϵÁС£


Zyxel Cloud CNM SecuManager´æÔÚδÊÚȨԶ³Ì´úÂëÖ´Ðзì϶£¬Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶ÒÔͨ¹ýÀÄÓÃõ辶Ϊ /live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids=µÄ APIŲÓôﵽԶ³Ì´úÂëÖ´ÐеÄÖ÷ÕÅ¡£


ר¼ÒÃÇ·¢ÏÖÁËÔ̺¬´Ë·ì϶ÔÚÄڵĹ²16¸ö·ì϶£¬Ô̺¬ÓÃÓÚ²»°²È«ÄÚ´æ´æ´¢µÄĬÈÏÍ´´¦ºÍºóÃÅ¡£×¨¼Ò·¢ÏÖµÄÎÊÌâµÄÆëÈ«ÁбíÈçÏ£º


1. Ó²±àÂëµÄSSH·þÎñÆ÷ÃÜÔ¿

2. MySQLÖеĺóÃÅÕÊ»§

3. EjabberdÖеÄÓ²±àÂëÖ¤ÊéºÍºóÃŽӼû

4. ÎÞÐèÉí·ÝÑéÖ¤¼´¿É´ò¿ªZODB´æ´¢

5. MyZyxel¡°ÔÆ¡±Ó²±àÂëµÄ°ÂÃØ

6. Ó²±àÂëµÄ»úÃÜ£¬API

7. ÖÎÀíÔ¹ØÊ»§µÄÔ¤Ô¼ÒåÃÜÂë

8. ¶Ô¡°ÔÆ¡±µÄ²»°²È«ÖÎÀí

9. xmppCnrSender.pyÈÕ־תÒåÐòÁÐ×¢Èë

10. xmppCnrSender.pyûÓÐÉí·ÝÑéÖ¤ºÍÃ÷ÎÄͨѶ

11. ÃýÎóµÄHTTPÒªÇóµ¼ÖÂZope³¬³öÁìÓò½Ó¼û

12. Web½çÃæÉϵÄXSS

13. ¸öÈËSSHÃÜÔ¿

14. ºóÃÅAPI

15. ºóÃÅÖÎÀí½Ó¼ûºÍRCE

16. ÓµÓÐchroot½Ó¼ûȨÏÞµÄÔ¤ÈÏÖ¤RCE


¾Ýͳ¼Æ£¬Zyxel Cloud CNM SecuManagerÔÚÖйú¶³öÔÚÍøÉϵÄÊýÁ¿ºÍÉ¢²¼ÈçÏÂͼ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


·ì϶ÑéÖ¤


PoC£ºhttps://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÉÐδÌṩÓйطì϶²¹¶¡Á´½Ó£¬Çë¹Ø×¢³§ÉÌÖ÷Ò³ËæÊ±¸üУºhttps://www.zyxel.cn/¡£


²Î¿¼Á´½Ó



https://www.cnvd.org.cn/flaw/show/CNVD-2020-16839