¡¾Â©¶´Í¨¸æ¡¿Zyxel ·À»ðǽ & APÉ豸¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2022-05-26
0x00 ©¶´¸ÅÊö
ºÏÇڿƼ¼(Zyxel Communications Corp.)ÊÇÒ»¼Ò¿ç¹ú¿í´ø½ÓÈë½â¾ö·½°¸ÌṩÉÌ¡£
2022Äê5ÔÂ24ÈÕ£¬ZyxelÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËÆä·À»ðǽ¡¢AP ¿ØÖÆÆ÷ºÍ APÉ豸ÖеĶà¸öÄþ¾²Â©¶´£¬ÕâЩ©¶´¿ÉÄܵ¼ÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡¢ÐÅϢй¶¡¢¾Ü¾ø·þÎñ»òÃüÁîÖ´ÐС£
0x01 ©¶´ÏêÇé
Zyxel´Ë´Î¹²ÐÞ¸´ÁËÓ°ÏìÆä¶à¸ö²úÎïÐͺŵÄ4¸ö©¶´£¬ÏêÇéÈçÏ£º
CVE-2022-0734£ºZyxel·À»ðǽ¿çÕ¾½Å±¾Â©¶´£¨ÖÐΣ£©
ZyxelijЩ·À»ðǽ°æ±¾µÄ CGI ·¨Ê½ÖдæÔÚ¿çÕ¾½Å±¾Â©¶´£¬¿Éͨ¹ý¶ñÒâ½Å±¾»ñÈ¡´æ´¢ÔÚÓû§ä¯ÀÀÆ÷ÖеÄijЩÐÅÏ¢£¬Èç cookie »ò»á»°ÁîÅÆ¡£
CVE-2022-26531£ºZyxel·À»ðǽ & APÉ豸»º³åÇøÒç³ö©¶´£¨ÖÐΣ£©
ZyxelijЩ·À»ðǽ¡¢AP¿ØÖÆÆ÷ºÍAPÉ豸µÄijЩCLIÃüÁîÖдæÔÚ²»ÕýÈ·µÄÊäÈëÑé֤©¶´£¬¿Éͨ¹ý¶ñÒâPayloadÔì³É»º³åÇøÒç³ö»òϵͳÍ߽⡣
CVE-2022-26532£ºZyxel·À»ðǽ & APÉ豸ÃüÁî×¢Èë©¶´£¨¸ßΣ£©
ZyxelijЩ·À»ðǽ¡¢AP¿ØÖÆÆ÷ºÍAPÉ豸µÄ¡°packet-trace¡±CLI ÃüÁîÖдæÔÚÃüÁî×¢Èë©¶´£¬¿Éͨ¹ýÔÚÃüÁîÖаüÂÞ¾«ÐÄÉè¼ÆµÄ²ÎÊýÀ´Ö´ÐÐÈÎÒâϵͳÃüÁî¡£
CVE-2022-0910£ºZyxel·À»ðǽÉí·ÝÑéÖ¤ÈÆ¹ý©¶´£¨ÖÐΣ£©
ÓÉÓÚȱ·¦Êʵ±µÄ·ÃÎÊ¿ØÖÆ»úÖÆ£¬ZyxelijЩ·À»ðǽ°æ±¾µÄCGI·¨Ê½ÖдæÔÚÉí·ÝÑéÖ¤ÈÆ¹ý©¶´£¬¿Éͨ¹ý IPsec VPN ¿Í»§¶Ë´ÓË«ÒòËØÉí·ÝÑéÖ¤½µ¼¶Îªµ¥ÒòËØÉí·ÝÑéÖ¤¡£
0x02 Äþ¾²½¨Òé
ĿǰÕâЩ©¶´ÒѾÐÞ¸´£¬½¨ÒéÊÜÓ°ÏìÓû§²Î¿¼ÏÂ±í¼°Ê±Éý¼¶¸üе½ÐÞ¸´°æ±¾£º
·À»ðǽÉ豸 | ÊÜÓ°Ïì°æ±¾ | ÐÞ¸´°æ±¾ | |||
CVE-2022-0734 | CVE-2022-26531 | CVE-2022-26532 | CVE-2022-0910 | ||
USG/ZyWALL | ZLD V4.35~V4.70 | ZLD V4.09~V4.71 | ZLD V4.09~V4.71 | ZLD V4.32~V4.71 | ZLD V4.72 |
USG FLEX | ZLD V4.50~V5.20 | ZLD V4.50~V5.21 | ZLD V4.50~V5.21 | ZLD V4.50~V5.21 | ZLD V5.30 |
ATP | ZLD V4.35~V5.20 | ZLD V4.32~V5.21 | ZLD V4.32~V5.21 | ZLD V4.32~V5.21 | ZLD V5.30 |
VPN | ZLD V4.35~V5.20 | ZLD V4.30~V5.21 | ZLD V4.30~V5.21 | ZLD V4.32~V5.21 | ZLD V5.30 |
NSG | ²»ÊÜÓ°Ïì | V1.00~V1.33 Patch 4 | V1.00~V1.33 Patch 4 | ²»ÊÜÓ°Ïì | V1.33 Patch 5 |
AP ¿ØÖÆÆ÷ | ÊÜÓ°Ïì°æ±¾ | ÐÞ¸´°æ±¾ |
CVE-2022-26531 ºÍCVE-2022-26532 | ||
NXC2500 | 6.10(AAIG.3) ¼°¸üÔç°æ±¾ | ÁªÏµÊÛºó |
NXC5500 | 6.10(AAOS.3) ¼°¸üÔç°æ±¾ |
APÉ豸 | ÊÜÓ°Ïì°æ±¾ | ÐÞ¸´°æ±¾ |
CVE-2022-26531 ºÍ CVE-2022-26532 | ||
NAP203 | 6.25(ABFA.7) ¼°¸üÔç°æ±¾ | 6.25(ABFA.8) |
NAP303 | 6.25(ABEX.7) ¼°¸üÔç°æ±¾ | 6.25(ABEX.8) |
NAP353 | 6.25(ABEY.7) ¼°¸üÔç°æ±¾ | 6.25(ABEY.8) |
NWA50AX | 6.25(ABYW.5) ¼°¸üÔç°æ±¾ | 6.25(ABYW.8) |
NWA55AXE | 6.25(ABZL.5) ¼°¸üÔç°æ±¾ | 6.25(ABZL.8) |
NWA90AX | 6.27(ACCV.2) ¼°¸üÔç°æ±¾ | 6.27(ACCV.3) |
NWA110AX | 6.30(ABTG.2) ¼°¸üÔç°æ±¾ | 6.30(ABTG.3) |
NWA210AX | 6.30(ABTD.2) ¼°¸üÔç°æ±¾ | 6.30(ABTD.3) |
NWA1123-AC-HD | 6.25(ABIN.6) ¼°¸üÔç°æ±¾ | 6.25(ABIN.8) |
NWA1123-AC-PRO | 6.25(ABHD.7) ¼°¸üÔç°æ±¾ | 6.25(ABHD.8) |
NWA1123ACv3 | 6.30(ABVT.2) ¼°¸üÔç°æ±¾ | 6.30(ABVT.3) |
NWA1302-AC | 6.25(ABKU.6) ¼°¸üÔç°æ±¾ | 6.25(ABKU.8) |
NWA5123-AC-HD | 6.25(ABIM.6) ¼°¸üÔç°æ±¾ | 6.25(ABIM.8) |
WAC500H | 6.30(ABWA.2) ¼°¸üÔç°æ±¾ | 6.30(ABWA.3) |
WAC500 | 6.30(ABVS.2) ¼°¸üÔç°æ±¾ | 6.30(ABVS.3) |
WAC5302D-S | 6.10(ABFH.10) ¼°¸üÔç°æ±¾ | ÁªÏµÊÛºó |
WAC5302D-Sv2 | 6.25(ABVZ.6) ¼°¸üÔç°æ±¾ | 6.25(ABVZ.8) |
WAC6103D-I | 6.25(AAXH.7) ¼°¸üÔç°æ±¾ | 6.25(AAXH.8) |
WAC6303D-S | 6.25(ABGL.6) ¼°¸üÔç°æ±¾ | 6.25(ABGL.8) |
WAC6502D-E | 6.25(AASD.7) ¼°¸üÔç°æ±¾ | 6.25(AASD.8) |
WAC6502D-S | 6.25(AASE.7) ¼°¸üÔç°æ±¾ | 6.25(AASE.8) |
WAC6503D-S | 6.25(AASF.7) ¼°¸üÔç°æ±¾ | 6.25(AASF.8) |
WAC6553D-E | 6.25(AASG.7) ¼°¸üÔç°æ±¾ | 6.25(AASG.8) |
WAC6552D-S | 6.25(ABIO.7) ¼°¸üÔç°æ±¾ | 6.25(ABIO.8) |
WAX510D | 6.30(ABTF.2) ¼°¸üÔç°æ±¾ | 6.30(ABTF.3) |
WAX610D | 6.30(ABTE.2) ¼°¸üÔç°æ±¾ | 6.30(ABTE.3) |
WAX630S | 6.30(ABZD.2) ¼°¸üÔç°æ±¾ | 6.30(ABZD.3) |
WAX650S | 6.30(ABRM.2) ¼°¸üÔç°æ±¾ | 6.30(ABRM.3) |
ÏÂÔØÁ´½Ó£º
https://www.zyxel.com/
0x03 ²Î¿¼Á´½Ó
https://www.zyxel.com/support/multiple-vulnerabilities-of-firewalls-AP-controllers-and-APs.shtml
https://nvd.nist.gov/vuln/detail/CVE-2022-26531
0x04 °æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2022-05-26 | Ê×´ÎÐû²¼ |
0x05 ¸½Â¼
¶«Éƽ̨¼ò½é
¶«Éƽ̨¹«Ë¾½¨Á¢ÓÚ1996Ä꣬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬ÊǹúÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÄþ¾²²úÎï¡¢¿ÉÐÅÄþ¾²¹ÜÀíÆ½Ì¨¡¢Äþ¾²·þÎñÓë½â¾ö·½°¸µÄ×ÛºÏÌṩÉÌ¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬ÓµÓÐÁýÕÖÈ«¹úµÄÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÖÐÐÄ£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£
¶àÄêÀ´£¬¶«Éƽ̨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£
¹ØÓÚ¶«Éƽ̨
¶«Éƽ̨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£
¹Ø×¢ÒÔϹ«Öںţ¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º