CVE-2020-12695 | UPnPЭÒéCallStrangerÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-06-09

0x00 Îó²î¸ÅÊö


CVE   ID

CVE-2020-12695

ʱ    ¼ä

2020-06-09

Àà    ÐÍ

µÈ    ¼¶

ÑÏÖØ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


0x01 Îó²îÏêÇé


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



ͨÓü´²å¼´Óã¨Universal Plug and Play£¬£¬£¬£¬¼ò³ÆUPnP£©ÊÇÓÉ¿ª·ÅÅþÁ¬»ù½ð»á£¨OCF£©ÖÎÀíµÄÒ»Ì×ÍøÂçЭÒé¡£¡£¡£¡£¡£¡£¸ÃЭÒéµÄÄ¿µÄÊÇʹ¼ÒÍ¥ÍøÂ磨Êý¾Ý¹²Ïí¡¢Í¨Ñ¶ºÍÓéÀÖ£©ºÍ¹«Ë¾ÍøÂçÖеÄÖÖÖÖ×°±¸Äܹ»Ï໥ÎÞ·ìÅþÁ¬£¬£¬£¬£¬²¢¼ò»¯Ïà¹ØÍøÂçµÄʵÏÖ¡£¡£¡£¡£¡£¡£UPnPͨ¹ý½ç˵ºÍÐû²¼»ùÓÚ¿ª·Å¡¢ÒòÌØÍøÍ¨Ñ¶ÍøÐ­Òé±ê×¼µÄUPnP×°±¸¿ØÖÆÐ­ÒéÀ´ÊµÏÖÕâһĿµÄ¡£¡£¡£¡£¡£¡£

2019Äê12Ô£¬£¬£¬£¬Ò»Î»Ãû½ÐYunus?adirciµÄÇå¾²¹¤³ÌʦÔÚÕâÏΪÆÕ¼°µÄÊÖÒÕÖз¢Ã÷ÁËÒ»¸öÎó²î£¨CVE-2020-12695£©£¬£¬£¬£¬ÃüÃûΪCallStranger¡£¡£¡£¡£¡£¡£ÔÚÊýÊ®ÒÚ¸öUPNP×°±¸Öз¢Ã÷µÄCallStrangerÎó²î¿Éµ¼ÖÂÊý¾Ýй¶£¨×ÝÈ»ÄúÓÐDLP/½çÏßÇå¾²×°±¸£©»òɨÃèÄúµÄÍøÂ磬£¬£¬£¬ÉõÖÁµ¼ÖÂÄúµÄÍøÂç¼ÓÈëDDoS¹¥»÷¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓÉUPnP SUBSCRIBEº¯ÊýÖеıêÍ·Öµ»Øµ÷ÒýÆð£¬£¬£¬£¬¹¥»÷Õß¿ÉÒԽṹһ¸öº¬ÖøÃûÌùýʧµÄ±êÍ·Öµ»Øµ÷µÄTCPÊý¾Ý°ü·¢Ë͵½Ô¶¶Ë×°±¸£¬£¬£¬£¬À´Ê¹Óû¥ÁªÍøÉÏÖ§³ÖUPnPЭÒéµÄÖÇÄÜ×°±¸£¬£¬£¬£¬ÀýÈçÉãÏñ»ú£¬£¬£¬£¬DVR£¬£¬£¬£¬´òÓ¡»ú£¬£¬£¬£¬Â·ÓÉÆ÷µÈ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î¾ÙÐÐÒÔϲÙ×÷£º

? ÈÆ¹ýDLPºÍÍøÂçÇå¾²×°±¸¿ÉÇÔÈ¡Êý¾Ý£»£»£»£»£»

? ʹÓÃÊý°ÙÍò¸öÃæÏòInternetµÄUPnP×°±¸×÷Ϊ·Å´óµÄ·´ÉäTCP DDoS/SYN FloodÔ´£»£»£»£»£»

? ´ÓÃæÏòInternetµÄUPnP×°±¸É¨ÃèÄÚ²¿¶Ë¿Ú¡£¡£¡£¡£¡£¡£

¸ÃÎó²îÓ°Ïì¹æÄ£´ó£¬£¬£¬£¬Ê¹ÓÃshodanɨÃè·¢Ã÷ԼĪÓÐ545Íǫ̀¿ªÆôUPnP¹¦Ð§µÄ×°±¸ÅþÁ¬µ½»¥ÁªÍø£¬£¬£¬£¬ÕâЩװ±¸ÈÝÒ׳ÉΪÎïÁªÍø½©Ê¬ÍøÂçºÍAPT×éÖ¯µÄ¹¥»÷Ä¿µÄ¡£¡£¡£¡£¡£¡£


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾




?adirciÌåÏÖ£¬£¬£¬£¬ËûÈ¥ÄêÔøÍ¨ÖªOCF£¬£¬£¬£¬¸Ã×éÖ¯ÒÑÓÚ2020Äê4ÔÂ17ÈÕ¸üÐÂÁËUPnPЭÒ鹿·¶¡£¡£¡£¡£¡£¡£ÓÉÓÚÕâÊÇÒ»¸öЭÒéÎó²î£¬£¬£¬£¬¹©Ó¦ÉÌ¿ÉÄÜÐèÒªºÜ³¤Ê±¼ä²Å»ªÌṩ²¹¶¡³ÌÐò¡£¡£¡£¡£¡£¡£

ÏÖÔÚÒѾ­È·ÈϵÄÊÜÓ°ÏìµÄÁбíÈçÏ£º

Xbox One- OS Version 10.0.19041.2494

ADB TNR-5720SX Box (TNR-5720SX/v16.4-rc-371-gf5e2289 UPnP/1.0 BH-upnpdev/2.0)

Asus ASUS Media Streamer

Asus Rt-N11

Belkin WeMo

Broadcom ADSL Modems

Canon Canon SELPHY CP1200 Printer

Cisco X1000 - (LINUX/2.4 UPnP/1.0 BRCM400/1.0)

Cisco X3500 - (LINUX/2.4 UPnP/1.0 BRCM400/1.0)

D-Link DVG-N5412SP WPS Router (OS 1.0 UPnP/1.0 Realtek/V1.3)

EPSON EP, EW, XP Series (EPSON_Linux UPnP/1.0 Epson UPnP SDK/1.0)

HP Deskjet, Photosmart, Officejet ENVY Series (POSIX, UPnP/1.0, Intel MicroStack/1.0.1347)

Huawei HG255s Router - Firmware HG255sC163B03 (ATP UPnP Core)

NEC AccessTechnica WR8165N Router ( OS 1.0 UPnP/1.0 Realtek/V1.3)

Philips 2k14MTK TV - Firmware TPL161E_012.003.039.001

Samsung UE55MU7000 TV - Firmware T-KTMDEUC-1280.5, BT - S

Samsung MU8000 TV

Siemens CNE1000 Camera

Sony Media Go Media application

Stream What You Hear Stream What You Hear

Toshiba TCC-C1 Media Device

TP-Link Archer C50

Trendnet TV-IP551W

Ubiquiti UniFi Controller

ZTE ZXV10 W300

ZTE H108N

Zyxel AMG1202-T10B


0x02 ´¦Öóͷ£½¨Òé


1. ÈôÊÇûÓÐÓªÒµ/ÊÖÒÕµÄÐèÇ󣬣¬£¬£¬½¨Ò鹨±Õµ½InternetµÄUPnP¶Ë¿Ú£»£»£»£»£»

2. ½¨Òé×è¶ÏSUBSCRIBEºÍNOTIFY HTTPÊý¾Ý°ü£»£»£»£»£»

3. ¼ì²éÈÕÖ¾£¬£¬£¬£¬È·ÈÏÊÇ·ñÓÐÈËʹÓôËÎó²î¡£¡£¡£¡£¡£¡£

±ðµÄ£¬£¬£¬£¬Ñо¿Ö°Ô±ÒѾ­Ðû²¼ÁËPoC£¬£¬£¬£¬Óû§¿ÉÒÔÓÃÀ´È·¶¨ÆäÖÇÄÜ×°±¸ÊÇ·ñÈÝÒ×Êܵ½CallStrangerÎó²îµÄ¹¥»÷¡£¡£¡£¡£¡£¡£

https://github.com/yunuscadirci/CallStranger


0x03 Ïà¹ØÐÂÎÅ


https://www.zdnet.com/article/callstranger-vulnerability-lets-attacks-bypass-security-systems-and-scan-lans/#ftag=RSSbaffb68


0x04 ²Î¿¼Á´½Ó


https://callstranger.com/

https://github.com/yunuscadirci/CallStranger

https://kb.cert.org/vuls/id/339275


0x05 ʱ¼äÏß


2020-06-08 Îó²î¹ûÕæ

2020-06-09 VSRCÐû²¼Îó²îͨ¸æ


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾