ÐÅÈñWACÏÂÁî×¢ÈëÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-05-21Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-9161£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
Ó°Ïì°æ±¾
ÐÅÈñWAC 3.7.4.2¼°Ö®Ç°°æ±¾
Îó²î¸ÅÊö
Sundray WLAN Controller£¨ÐÅÈñWAC£©ÊÇÖйúÐÅÈñÍø¿ÆÊÖÒÕ£¨Sundray£©¹«Ë¾µÄÒ»Ì×ÎÞÏß¾ÖÓòÍø¿ØÖÆÆ÷Èí¼þ¡£¡£¡£¡£¡£¡£¡£¡£ÐÅÈñ¿Æ¼¼Ö÷ҪӪҵΪÆóÒµ¼¶ÎÞÏßÍøÂç¡¢ÎïÁªÍøÒÔ¼°ÖÇÄܽ»Á÷»ú²úÆ·µÄ¿ª·¢¡¢Ó¦Ó㬣¬£¬£¬£¬ÐÐÒµ¿Í»§×ÜÁ¿Áè¼Ý55000¼Ò¡£¡£¡£¡£¡£¡£¡£¡£¾ÝIDCÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬2018Ä꣬£¬£¬£¬£¬ÐÅÈñÎÞÏßÔÚÖйúÆóÒµ¼¶WLANÊг¡ÅÅÃûµÚÈý¡£¡£¡£¡£¡£¡£¡£¡£
ÎÞÏß¿ØÖÆÆ÷Ó²¼þ(AC)±£´æÒ»¸öÎÞÐèµÇ¼µÄRCEÎó²î²¢¿Éͨ¹ýWebUI¹¦Ð§È±ÏÝÖ±½Ó»ñȡװ±¸µÄroot¿ØÖÆÈ¨ÏÞ¡£¡£¡£¡£¡£¡£¡£¡£AC×°±¸ÍùÍùÊÇÒ»¸öÆóÒµ°ì¹«ÍøÂçµÄÉÏÍøÈë¿Ú£¬£¬£¬£¬£¬¶Ô½ÓÆóÒµÈÏ֤ϵͳ£¨LDAPµÈ£©£¬£¬£¬£¬£¬²¢Äܹ»Á¬Í¨¸÷Éú²ú¡¢°ì¹«ÍøÂ磨OA¡¢GitlabµÈ£©¡£¡£¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÀ´ËÎó²î»ñÈ¡ÆóÒµÄÚÍøÖÜÓεÄ;¾¶£¬£¬£¬£¬£¬½ø¶øÕö¿ª¶ÔÆóÒµÄÚÍøµÄÒ»Á¬ÉøÍ¸ºÍ¹¥»÷£¨APT£©¡£¡£¡£¡£¡£¡£¡£¡£
Ô¶³Ì¹¥»÷Õ߿ɽèÖúnginx_webconsole.php°üÍ·ÖеÄshellÔª×Ö·û¶ÁÈ¡´øÓÐadminÃÜÂëµÄetc/config/wac/wns_cfg_admin_detail.xmlÎļþ£¬£¬£¬£¬£¬Ê¹ÓøÃÎó²î»ñȡϵͳµÄËùÓÐȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC¡¢EXP¡£¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
http://www.sundray.com.cn
²Î¿¼Á´½Ó
https://nvd.nist.gov/vuln/detail/CVE-2019-9161


¾©¹«Íø°²±¸11010802024551ºÅ