¡¾·ì϶¹«¸æ¡¿Realtek SDK 8Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-08-170x00 ·ì϶¸ÅÊö
2021Äê8ÔÂ16ÈÕ£¬×êÑÐÈËÔ±¹«¿ªÅû¶ÁĘ̈ÍåоƬÉè¼ÆÉÌRealtek¹«Ë¾µÄ SDKÖеÄ4¸ö°²È«·ì϶£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÄÜÀûÓÃÕâЩ·ì϶ʹÉ豸±ÀÀ££¨»Ø¾ø·þÎñ£©¡¢×¢ÈëËÁÒâºÅÁî²¢ÒÔ×î¸ßȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£ÕâЩ·ì϶ÖÁÉÙÓ°ÏìÁË65¸ö·ÖÆç¹©¸øÉ̳ö²úµÄ½ü 200 ÖÖ²úÆ·£¬²¢ÇÒ×÷Ϊ¹©¸øÁ´·ì϶£¬ËüÃÇÓ°ÏìÁ˹©¸øÁ´ÏÂÓεÄÊýÊ®Íǫ̀É豸¡£
0x01 ·ì϶ÏêÇé

ÔÚÎïÁªÍøÁìÓòµÄºÜ¶àǶÈëʽÉ豸Öж¼Äܹ»ÕÒµ½ Realtek оƬ×é¡£×êÑÐÈËÔ±°µÊ¾£¬³¬¹ý 65 ¼ÒÓ²¼þÔì×÷É̵IJúƷѡȡÁË Realtek RTL819xD Ä£¿é£¬¸ÃÄ£¿éʵÏÖÁËÎÞÏß½ÓÈëµãÖ°Äܲ¢Ô̺¬ÆäÖÐÒ»¸öÒ×Êܹ¥»÷µÄ SDK¡£²¢ÇÒÊÜÓ°ÏìµÄÉ豸ʹÓÃ¿í·º£¬´Ó×¡Õ¬Íø¹Ø¡¢¹Û¹â·ÓÉÆ÷¡¢Wi-Fi ÖÐ¼ÌÆ÷¡¢IP ÉãÏñ»úµ½ÖÇÄÜÉÁµçÍø¹Ø£¬ÉõÖÁÊÇÁªÍøÍæ¾ß¡£
×êÑÐÈËÔ±Åû¶µÄ4¸ö·ì϶ÈçÏ£¬ÆäÖÐǰ2¸ö·ì϶µÄCVSSÆÀ·ÖΪ8.1£¨¸ßΣ£©£¬ºó2¸ö·ì϶µÄCVSSÆÀ·ÖΪ9.8£¨ÑϳÁ£©¡£µ«ÒªÀûÓÃÕâЩ·ì϶£¬¹¥»÷ÕßÐèÓëÉ豸ÔÚÍ³Ò»ÍøÂ磬»òÕß¿ÉÄÜͨ¹ý»¥ÁªÍø½Ó¼ûÉ豸¡£
l CVE-2021-35392£ºÍ¨¹ý UPnP µÄ Wi-Fi µ¥Ò»ÅäÖòֿ⻺³åÇøÒç³ö
l CVE-2021-35393£ºÍ¨¹ý SSDP µÄ Wi-Fi µ¥Ò»ÅäÖöѻº³åÇøÒç³ö
l CVE-2021-35394£ºMP Daemon Õï¶Ï¹¤¾ßºÅÁî×¢Èë
l CVE-2021-35395£ºÖÎÀíWeb½çÃæ¶à¸ö·ì϶
Ó°ÏìÁìÓò
Realtek SDK v2.x
Realtek ¡°Jungle¡± SDK v3.0/v3.1/v3.2/v3.4.x/v3.4T/v3.4T-CT
Realtek ¡°Luna¡± SDK ×î¸ß°æ±¾ 1.3.2
0x02 ´ëÖý¨Òé
ĿǰÕâЩ·ì϶ÒѾÔÚ²¿ÃŰ汾Öн¨¸´¡£½¨Òé²Î¿¼ÒÔϰ汾ʵʱÉý¼¶¸üÐÂ:
Realtek SDK branch 2.x£ºRealtek²»ÔÙÖ§³Ö¡£
Realtek "Jungle" SDK£ºRealtekÔÚ¿ª·¢²¹¶¡£¬ÐèÏòºóÒÆÖ²
Realtek "Luna" SDK£ºÉý¼¶µ½1.3.2a
ÏÂÔØÁ´½Ó£º
https://www.realtek.com/en/cu-1-en/cu-1-taiwan-en
ÒÑÖªµÄÊÜÓ°ÏìÔì×÷É̼°²úÆ·Á´½ÓÈçÏ£º£¨Éæ¼°D-Link¡¢»ªÎª¡¢ÁªÍ¨¡¢ºÏÇڵȣ©
https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain/
0x03 ²Î¿¼Á´½Ó
https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain/
https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf
https://www.theregister.com/2021/08/16/realtek_wifi_sdk_vulnerabilities/
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2021-08-17 | ³õ´Î°ä²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚGA»Æ½ð¼×
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ