ZyXEL Cloud CNM SecuManagerδÊÚȨԶ³Ì´úÂëÖ´Ðзì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-03-16·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ZyXEL Cloud CNM SecuManager <=3.1.1
·ì϶¸ÅÊö
Zyxel Cloud CNM SecuManagerÊÇÒ»¿îÈ«ÃæµÄÍøÂçÖÎÀíÈí¼þ£¬¿ÉÌṩ¼¯³É½ÚÔį̀À´¼à¶½ºÍÖÎÀí°²È«Íø¹Ø£¬Ô̺¬ZyWALLUSGºÍVPNϵÁС£
Zyxel Cloud CNM SecuManager´æÔÚδÊÚȨԶ³Ì´úÂëÖ´Ðзì϶£¬Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶ÒÔͨ¹ýÀÄÓÃõ辶Ϊ /live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids=µÄ APIŲÓôﵽԶ³Ì´úÂëÖ´ÐеÄÖ÷ÕÅ¡£
ר¼ÒÃÇ·¢ÏÖÁËÔ̺¬´Ë·ì϶ÔÚÄڵĹ²16¸ö·ì϶£¬Ô̺¬ÓÃÓÚ²»°²È«ÄÚ´æ´æ´¢µÄĬÈÏÍ´´¦ºÍºóÃÅ¡£×¨¼Ò·¢ÏÖµÄÎÊÌâµÄÆëÈ«ÁбíÈçÏ£º
1. Ó²±àÂëµÄSSH·þÎñÆ÷ÃÜÔ¿
2. MySQLÖеĺóÃÅÕÊ»§
3. EjabberdÖеÄÓ²±àÂëÖ¤ÊéºÍºóÃŽӼû
4. ÎÞÐèÉí·ÝÑéÖ¤¼´¿É´ò¿ªZODB´æ´¢
5. MyZyxel¡°ÔÆ¡±Ó²±àÂëµÄ°ÂÃØ
6. Ó²±àÂëµÄ»úÃÜ£¬API
7. ÖÎÀíÔ¹ØÊ»§µÄÔ¤Ô¼ÒåÃÜÂë
8. ¶Ô¡°ÔÆ¡±µÄ²»°²È«ÖÎÀí
9. xmppCnrSender.pyÈÕ־תÒåÐòÁÐ×¢Èë
10. xmppCnrSender.pyûÓÐÉí·ÝÑéÖ¤ºÍÃ÷ÎÄͨѶ
11. ÃýÎóµÄHTTPÒªÇóµ¼ÖÂZope³¬³öÁìÓò½Ó¼û
12. Web½çÃæÉϵÄXSS
13. ¸öÈËSSHÃÜÔ¿
14. ºóÃÅAPI
15. ºóÃÅÖÎÀí½Ó¼ûºÍRCE
16. ÓµÓÐchroot½Ó¼ûȨÏÞµÄÔ¤ÈÏÖ¤RCE
¾Ýͳ¼Æ£¬Zyxel Cloud CNM SecuManagerÔÚÖйú¶³öÔÚÍøÉϵÄÊýÁ¿ºÍÉ¢²¼ÈçÏÂͼ£º
·ì϶ÑéÖ¤
PoC£ºhttps://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÉÐδÌṩÓйطì϶²¹¶¡Á´½Ó£¬Çë¹Ø×¢³§ÉÌÖ÷Ò³ËæÊ±¸üУºhttps://www.zyxel.cn/¡£
²Î¿¼Á´½Ó
https://www.cnvd.org.cn/flaw/show/CNVD-2020-16839


¾©¹«Íø°²±¸11010802024551ºÅ