D-Link DNS-320×°±¸Ô¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-09-24

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-16057 £¬Î£ÏÕ¼¶±ð£ºÑÏÖØ £¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


D-Link DNS-320 2.05.B10¼°Ö®Ç°°æ±¾


Îó²î¸ÅÊö


D-Link DNS-320ÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îNAS£¨ÍøÂçÁ¥Êô´æ´¢£©×°±¸ ¡£


Ñо¿Ö°Ô±·¢Ã÷D-Link DNS-320 ShareCenter×°±¸±£´æÒ»¸öÏÂÁî×¢ÈëÎó²î £¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÔ¶³Ì¿ØÖÆ×°±¸²¢»á¼û×°±¸ÉÏ´æ´¢µÄÎļþ ¡£


ƾ֤Ñо¿Ö°Ô±µÄ±¨¸æ £¬¸ÃÎó²îÓëDNS-320¹ÜÀí½çÃæµÄSSL LoginµÄÒþ²Ø¹¦Ð§ÓÐ¹Ø £¬ÊÜÓ°ÏìµÄÄ£¿é/cgi/login_mgr.cgi°üÀ¨Ò»¸ö¿ÉÄܱ»Ê¹ÓõIJÎÊýport £¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚrootȨÏÞÏÂÖ´ÐÐí§ÒâÏÂÁî £¬´Ó¶øµ¼ÖÂ×°±¸±»½ÓÊÜ ¡£ 

 

Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


Îó²îÑéÖ¤

 

Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î £¬¼û²Î¿¼Á´½Ó ¡£


²Î¿¼Á´½Ó


https://blog.cystack.net/d-link-dns-320-rce/