Davolink DVW-3200N·ÓÉÆ÷¸ßΣÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-08-02

Îó²î±àºÅºÍ¼¶±ð


CVE-2018-10618  ³§ÉÌ×ÔÆÀ£º9.8   CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾£º


DVW-3200N version < 1.00.06


²»ÊÜÓ°ÏìµÄ°æ±¾£º


DVW-3200N version 1.00.06


Îó²î¸ÅÊö


7ÔÂ31ÈÕ£¬Davolink DVW-3200N ·ÓÉÆ÷±»ÆØ³ö1¸ö¸ßΣÎó²î£¨CVE-2018-10618£©¡£¸Ã·ÓÉÆ÷ÌìÉúÈÝÒ×±»ÆÆ½âµÄÈõÃÜÂ룬ÔÊÐíÔ¶³Ì¹¥»÷Õß»ñȡװ±¸µÄÃÜÂë¡£


Davolink DVW-3200N ·ÓÉÆ÷µÄ¶Ë¿Ú88ÉÏÓеǼÃÅ»§£¬»á¼ûÊÜÃÜÂë± £»¤£¬µ«ÃÜÂëÔÚµÇÂ¼Ò³ÃæµÄHTMLÖÐÊÇÓ²±àÂëµÄ¡£ÆÊÎöÒ³Ãæ´úÂ룬һ¸öÃûΪ¡°clickApply¡±µÄº¯Êý£¬ÆäÖаüÀ¨±ê×¼base 64±àÂëÖеÄÃÜÂë¡£


Îó²îʹÓÃ


Îó²îʹÓôúÂ룺https://cxsecurity.com/issue/WLB-2018070219¡£


ÐÞ¸´½¨Òé


Davolink¹Ù·½Îª¸Ã×°±¸ÌṩÁËÒ»¸öеĹ̼þ°æ±¾£¬¿ÉÒÔ´ÓÒÔÏÂÁ´½ÓÏÂÔØ£ºhttp://www.davolink.co.kr/sys/bbs/board.php?bo_table=0403&wr_id=50¡£


²Î¿¼Á´½Ó


http://www.davolink.co.kr/sys/bbs/board.php?bo_table=0403&wr_id=50


https://ics-cert.us-cert.gov/advisories/ICSA-18-212-01


https://cxsecurity.com/issue/WLB-2018070219