D-Link DNS-320×°±¸Ô¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-09-24

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-16057£¬ £¬ £¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬ £¬ £¬£¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


D-Link DNS-320 2.05.B10¼°Ö®Ç°°æ±¾


Îó²î¸ÅÊö


D-Link DNS-320ÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îNAS£¨ÍøÂçÁ¥Êô´æ´¢£©×°±¸¡£¡£¡£¡£¡£


Ñо¿Ö°Ô±·¢Ã÷D-Link DNS-320 ShareCenter×°±¸±£´æÒ»¸öÏÂÁî×¢ÈëÎó²î£¬ £¬ £¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÔ¶³Ì¿ØÖÆ×°±¸²¢»á¼û×°±¸ÉÏ´æ´¢µÄÎļþ¡£¡£¡£¡£¡£


ƾ֤Ñо¿Ö°Ô±µÄ±¨¸æ£¬ £¬ £¬£¬¸ÃÎó²îÓëDNS-320ÖÎÀí½çÃæµÄSSL LoginµÄÒþ²Ø¹¦Ð§ÓйØ£¬ £¬ £¬£¬ÊÜÓ°ÏìµÄÄ£¿£¿£¿é/cgi/login_mgr.cgi°üÀ¨Ò»¸ö¿ÉÄܱ»Ê¹ÓõIJÎÊýport£¬ £¬ £¬£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚrootȨÏÞÏÂÖ´ÐÐí§ÒâÏÂÁ £¬ £¬£¬´Ó¶øµ¼ÖÂ×°±¸±»½ÓÊÜ¡£¡£¡£¡£¡£ 

 

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Îó²îÑéÖ¤

 

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬ £¬ £¬£¬¼û²Î¿¼Á´½Ó¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://blog.cystack.net/d-link-dns-320-rce/