TP-LinkÐÞ¸´Archer·ÓÉÆ÷Éí·ÝÑéÖ¤ÈÆ¹ýÎó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2019-12-17

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-7405£¬£¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


Archer C5 V4¡¢Archer MR200v4¡¢Archer MR6400v4ºÍArcher MR400v3·ÓÉÆ÷


Îó²î¸ÅÊö


TP-LinkÐÞ¸´²¿·ÖArcher·ÓÉÆ÷ÖеÄÇå¾²Îó²î£¬£¬£¬£¬ £¬£¬£¬¸ÃÎó²îʹµÃ¹¥»÷Õß¿ÉÒÔÎÞÐèÖÎÀíÔ±ÃÜÂë¼´¿É½ÓÊÜ×°±¸¡£¡£ ¡£¡£¹¥»÷Õß¿Éͨ¹ý·¢ËÍ×Ö·û´®³¤¶ÈÁè¼ÝÔÊÐíµÄ×Ö½ÚÊýµÄHTTPÇëÇ󣬣¬£¬£¬ £¬£¬£¬Ê¹µÃÓû§ÃÜÂë±»Ìæ»»Îª¿ÕÖµ£¬£¬£¬£¬ £¬£¬£¬´Ó¶ø»ñµÃ·ÓÉÆ÷µÄadminȨÏÞ¡£¡£ ¡£¡£¸Ã¹¥»÷»¹»áʹÕýµ±Óû§±»Ëø¶¨£¬£¬£¬£¬ £¬£¬£¬²¢ÇÒÎÞ·¨Í¨¹ýÓû§½çÃæµÇ¼WebЧÀÍ£¨ÃÜÂë±»Çå¿Õ¶øÓû§²¢²»ÖªÇ飩¡£¡£ ¡£¡£


Ö»¹Ü±£´æÄÚÖÃÑéÖ¤£¬£¬£¬£¬ £¬£¬£¬µ«Ð§¹ûÒÀÈ»ÔÆÔÆ£¬£¬£¬£¬ £¬£¬£¬ÓÉÓÚÄÚÖÃÑéÖ¤½ö»á¼ì²éÒýÓÃµÄ HTTP ±êÍ·£¬£¬£¬£¬ £¬£¬£¬µ¼Ö¹¥»÷Õßͨ¹ýʹÓÃÓ²±àÂëµÄ tplinkwifi.netÖµÓÕÆ­Â·ÓÉÆ÷µÄ httpd ЧÀÍÒÔΪÇëÇóÊÇÕýµ±µÄ¡£¡£ ¡£¡£


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



ÈçÏÂͼ£¬£¬£¬£¬ £¬£¬£¬½öʹÓá° admin¡±×÷ΪÓû§Ãû¼´¿É»á¼ûTELNETºÍFTP£¬£¬£¬£¬ £¬£¬£¬¶øÎÞÐèÊäÈëÈκÎÃÜÂ룬£¬£¬£¬ £¬£¬£¬Ä¬ÈÏÇéÐÎÏ£¬£¬£¬£¬ £¬£¬£¬¸ÃÓû§ÃûÊÇ×°±¸ÉÏΨһ¿ÉÓõÄÓû§¡£¡£ ¡£¡£


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



Îó²îÑéÖ¤


POC£ºhttps://securityintelligence.com/posts/tp-link-archer-router-vulnerability-voids-admin-password-can-allow-remote-takeover/¡£¡£ ¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐÞ¸´Îó²î£¬£¬£¬£¬ £¬£¬£¬½¨ÒéÓû§¾¡¿ì×°Öò¹¶¡£¡£ ¡£¡£º


Archer C5 V4£ºhttps://static.tp-link.com/2019/201909/20190917/Archer_C5v4190815.rar

Archer MR200v4£ºhttps://static.tp-link.com/2019/201909/20190903/Archer%20MR200(EU)_V4_20190730.zip

Archer MR6400v4£ºhttps://static.tp-link.com/2019/201908/20190826/Archer%20MR6400(EU)_V4_20190730.zip

Archer MR400v3£ºhttps://static.tp-link.com/2019/201908/20190826/Archer%20MR400(EU)_V3_20190730.zip


²Î¿¼Á´½Ó


https://securityintelligence.com/posts/tp-link-archer-router-vulnerability-voids-admin-password-can-allow-remote-takeover/