NETGEARÎÞÏß·ÓÉÆ÷DoSÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-09-11¡ñÎó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-5054£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-5055£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½Î´ÆÀ¶¨
¡ñÓ°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
NETGEAR N300 WNR2000v5 Firmware Version V1.0.0.70
¡ñÎó²î¸ÅÊö
˼¿ÆTalos·¢Ã÷NETGEAR N300ϵÁÐÎÞÏß·ÓÉÆ÷°üÀ¨Á½¸ö¾Ü¾ø·þÎñÎó²î¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÏò·ÓÉÆ÷µÄ²î±ð¹¦Ð§·¢ËͶñÒâSOAPºÍHTTPÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î£¬´Ó¶øµ¼ÖÂÆäÍêÈ«Í߽⡣
µÚÒ»¸öÎó²îÊÇCVE-2019-5054£¬±£´æÓÚHTTP·þÎñÆ÷µÄ»á»°´¦Öóͷ£¹¦Ð§ÖУ¬·¢Ë͵½Éí·ÝÑéÖ¤Ò³ÃæµÄ¿ÕUser-Agent×Ö·û´®HTTPÇëÇó¿ÉÄܵ¼Ö¿ÕÖ¸Õë½âÒýÓ㬴Ӷøµ¼ÖÂHTTP·þÎñÍ߽⡣
µÚ¶þ¸öÎó²îÊÇCVE-2019-5055£¬±£´æÓÚÖ÷ʱ»ú¼ûµãÊØ»¤³ÌÐò£¨hostapd£©ÖУ¬·¢Ë͵½<WFAWLANConfig£º1££PutMessage>·þÎñµÄÎÞЧÐòÁÐSOAPÇëÇó¿ÉÄܵ¼Ö¿ÕÖ¸Õë½âÒýÓ㬴Ӷøµ¼ÖÂhostapd·þÎñÍ߽⡣
¡ñÎó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£
¡ñÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://kb.netgear.com/000061228/WNR2000v5-Firmware-Version-1-0-0-72¡£
¡ñ²Î¿¼Á´½Ó
https://blog.talosintelligence.com/2019/09/vuln-spotlight-Netgear-N300-routers-DoS-sept-2019.html


¾©¹«Íø°²±¸11010802024551ºÅ