¡¾Â©¶´Í¨¸æ¡¿Zyxel ·À»ðǽ & APÉ豸¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2022-05-26

 

0x00 ©¶´¸ÅÊö

ºÏÇڿƼ¼(Zyxel Communications Corp.)ÊÇÒ»¼Ò¿ç¹ú¿í´ø½ÓÈë½â¾ö·½°¸ÌṩÉÌ¡£

2022Äê5ÔÂ24ÈÕ £¬ZyxelÐû²¼Äþ¾²Í¨¸æ £¬ÐÞ¸´ÁËÆä·À»ðǽ¡¢AP ¿ØÖÆÆ÷ºÍ APÉ豸ÖеĶà¸öÄþ¾²Â©¶´ £¬ÕâЩ©¶´¿ÉÄܵ¼ÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡¢ÐÅϢй¶¡¢¾Ü¾ø·þÎñ»òÃüÁîÖ´ÐС£

 

0x01 ©¶´ÏêÇé

Zyxel´Ë´Î¹²ÐÞ¸´ÁËÓ°ÏìÆä¶à¸ö²úÎïÐͺŵÄ4¸ö©¶´ £¬ÏêÇéÈçÏ£º

CVE-2022-0734£ºZyxel·À»ðǽ¿çÕ¾½Å±¾Â©¶´£¨ÖÐΣ£©

ZyxelijЩ·À»ðǽ°æ±¾µÄ CGI ·¨Ê½ÖдæÔÚ¿çÕ¾½Å±¾Â©¶´ £¬¿Éͨ¹ý¶ñÒâ½Å±¾»ñÈ¡´æ´¢ÔÚÓû§ä¯ÀÀÆ÷ÖеÄijЩÐÅÏ¢ £¬Èç cookie »ò»á»°ÁîÅÆ¡£

CVE-2022-26531£ºZyxel·À»ðǽ & APÉ豸»º³åÇøÒç³ö©¶´£¨ÖÐΣ£©

ZyxelijЩ·À»ðǽ¡¢AP¿ØÖÆÆ÷ºÍAPÉ豸µÄijЩCLIÃüÁîÖдæÔÚ²»ÕýÈ·µÄÊäÈëÑé֤©¶´ £¬¿Éͨ¹ý¶ñÒâPayloadÔì³É»º³åÇøÒç³ö»òϵͳÍ߽⡣

CVE-2022-26532£ºZyxel·À»ðǽ & APÉ豸ÃüÁî×¢Èë©¶´£¨¸ßΣ£©

ZyxelijЩ·À»ðǽ¡¢AP¿ØÖÆÆ÷ºÍAPÉ豸µÄ¡°packet-trace¡±CLI ÃüÁîÖдæÔÚÃüÁî×¢Èë©¶´ £¬¿Éͨ¹ýÔÚÃüÁîÖаüÂÞ¾«ÐÄÉè¼ÆµÄ²ÎÊýÀ´Ö´ÐÐÈÎÒâϵͳÃüÁî¡£

CVE-2022-0910£ºZyxel·À»ðǽÉí·ÝÑéÖ¤ÈÆ¹ý©¶´£¨ÖÐΣ£©

ÓÉÓÚȱ·¦Êʵ±µÄ·ÃÎÊ¿ØÖÆ»úÖÆ £¬ZyxelijЩ·À»ðǽ°æ±¾µÄCGI·¨Ê½ÖдæÔÚÉí·ÝÑéÖ¤ÈÆ¹ý©¶´ £¬¿Éͨ¹ý IPsec VPN ¿Í»§¶Ë´ÓË«ÒòËØÉí·ÝÑéÖ¤½µ¼¶Îªµ¥ÒòËØÉí·ÝÑéÖ¤¡£

 

0x02 Äþ¾²½¨Òé

ĿǰÕâЩ©¶´ÒѾ­ÐÞ¸´ £¬½¨ÒéÊÜÓ°ÏìÓû§²Î¿¼ÏÂ±í¼°Ê±Éý¼¶¸üе½ÐÞ¸´°æ±¾£º

·À»ðǽÉ豸

ÊÜÓ°Ïì°æ±¾

ÐÞ¸´°æ±¾

CVE-2022-0734

CVE-2022-26531

CVE-2022-26532

CVE-2022-0910

USG/ZyWALL

ZLD   V4.35~V4.70

ZLD   V4.09~V4.71

ZLD   V4.09~V4.71

ZLD   V4.32~V4.71

ZLD V4.72

USG FLEX

ZLD V4.50~V5.20

ZLD   V4.50~V5.21

ZLD   V4.50~V5.21

ZLD   V4.50~V5.21

ZLD V5.30

ATP

ZLD   V4.35~V5.20

ZLD   V4.32~V5.21

ZLD   V4.32~V5.21

ZLD   V4.32~V5.21

ZLD V5.30

VPN

ZLD   V4.35~V5.20

ZLD   V4.30~V5.21

ZLD   V4.30~V5.21

ZLD   V4.32~V5.21

ZLD V5.30

NSG

²»ÊÜÓ°Ïì

V1.00~V1.33   Patch 4

V1.00~V1.33   Patch 4

²»ÊÜÓ°Ïì

V1.33 Patch   5


AP ¿ØÖÆÆ÷

ÊÜÓ°Ïì°æ±¾

ÐÞ¸´°æ±¾

CVE-2022-26531 ºÍCVE-2022-26532

NXC2500

6.10(AAIG.3) ¼°¸üÔç°æ±¾

ÁªÏµÊÛºó

NXC5500

6.10(AAOS.3) ¼°¸üÔç°æ±¾


APÉ豸

ÊÜÓ°Ïì°æ±¾

ÐÞ¸´°æ±¾

CVE-2022-26531   ºÍ CVE-2022-26532

NAP203

6.25(ABFA.7) ¼°¸üÔç°æ±¾

6.25(ABFA.8)

NAP303

6.25(ABEX.7) ¼°¸üÔç°æ±¾

6.25(ABEX.8)

NAP353

6.25(ABEY.7) ¼°¸üÔç°æ±¾

6.25(ABEY.8)

NWA50AX

6.25(ABYW.5) ¼°¸üÔç°æ±¾

6.25(ABYW.8)

NWA55AXE

6.25(ABZL.5) ¼°¸üÔç°æ±¾

6.25(ABZL.8)

NWA90AX

6.27(ACCV.2) ¼°¸üÔç°æ±¾

6.27(ACCV.3)

NWA110AX

6.30(ABTG.2) ¼°¸üÔç°æ±¾

6.30(ABTG.3)

NWA210AX

6.30(ABTD.2) ¼°¸üÔç°æ±¾

6.30(ABTD.3)

NWA1123-AC-HD

6.25(ABIN.6) ¼°¸üÔç°æ±¾

6.25(ABIN.8)

NWA1123-AC-PRO

6.25(ABHD.7) ¼°¸üÔç°æ±¾

6.25(ABHD.8)

NWA1123ACv3

6.30(ABVT.2) ¼°¸üÔç°æ±¾

6.30(ABVT.3)

NWA1302-AC

6.25(ABKU.6) ¼°¸üÔç°æ±¾

6.25(ABKU.8)

NWA5123-AC-HD

6.25(ABIM.6) ¼°¸üÔç°æ±¾

6.25(ABIM.8)

WAC500H

6.30(ABWA.2) ¼°¸üÔç°æ±¾

6.30(ABWA.3)

WAC500

6.30(ABVS.2) ¼°¸üÔç°æ±¾

6.30(ABVS.3)

WAC5302D-S

6.10(ABFH.10) ¼°¸üÔç°æ±¾

ÁªÏµÊÛºó

WAC5302D-Sv2

6.25(ABVZ.6) ¼°¸üÔç°æ±¾

6.25(ABVZ.8)

WAC6103D-I

6.25(AAXH.7) ¼°¸üÔç°æ±¾

6.25(AAXH.8)

WAC6303D-S

6.25(ABGL.6) ¼°¸üÔç°æ±¾

6.25(ABGL.8)

WAC6502D-E

6.25(AASD.7) ¼°¸üÔç°æ±¾

6.25(AASD.8)

WAC6502D-S

6.25(AASE.7) ¼°¸üÔç°æ±¾

6.25(AASE.8)

WAC6503D-S

6.25(AASF.7) ¼°¸üÔç°æ±¾

6.25(AASF.8)

WAC6553D-E

6.25(AASG.7) ¼°¸üÔç°æ±¾

6.25(AASG.8)

WAC6552D-S

6.25(ABIO.7) ¼°¸üÔç°æ±¾

6.25(ABIO.8)

WAX510D

6.30(ABTF.2) ¼°¸üÔç°æ±¾

6.30(ABTF.3)

WAX610D

6.30(ABTE.2) ¼°¸üÔç°æ±¾

6.30(ABTE.3)

WAX630S

6.30(ABZD.2) ¼°¸üÔç°æ±¾

6.30(ABZD.3)

WAX650S

6.30(ABRM.2) ¼°¸üÔç°æ±¾

6.30(ABRM.3)

 

ÏÂÔØÁ´½Ó£º

https://www.zyxel.com/

 

0x03 ²Î¿¼Á´½Ó

https://www.zyxel.com/support/multiple-vulnerabilities-of-firewalls-AP-controllers-and-APs.shtml

https://nvd.nist.gov/vuln/detail/CVE-2022-26531

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-05-26

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨¹«Ë¾½¨Á¢ÓÚ1996Äê £¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊÐ £¬ÊǹúÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÄþ¾²²úÎï¡¢¿ÉÐÅÄþ¾²¹ÜÀíÆ½Ì¨¡¢Äþ¾²·þÎñÓë½â¾ö·½°¸µÄ×ÛºÏÌṩÉÌ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ° £¬ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹ £¬ÓµÓÐÁýÕÖÈ«¹úµÄÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÖÐÐÄ £¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£

¶àÄêÀ´ £¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ £¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£


¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£

¹Ø×¢ÒÔϹ«ÖںŠ£¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º

image.png