ÿÖÜÉý¼¶Í¨¸æ-2022-03-01

Ðû²¼Ê±¼ä 2022-03-01

ÐÂÔöʼþ

 

ʼþÃû³Æ£º

UDP_Äþ¾²Â©¶´_Realtek_sdk_udp·þÎñÔ¶³ÌÃüÁîÖ´ÐÐ[CVE-2021-35394]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÉ豸ÕýÔÚÀûÓÃRealtekSdkʹÓÃudp·þÎñ½á¹¹¶ñÒâÃüÁî¹¥»÷Ä¿µÄIPÉ豸¡£Ì¨ÍåоƬÉè¼ÆÉÌRealtek¾¯¸æÆäWiFiÄ£¿é¸½´øµÄÈý¸öÈí¼þ¿ª·¢¹¤¾ß°ü(SDK)ÖдæÔÚËĸöÄþ¾²Â©¶´ £¬ÕâЩÈí¼þ¿ª·¢¹¤¾ß°üÓÃÓÚÖÁÉÙ65¼Ò¹©Ó¦ÉÌÉú²úµÄ½ü200¿îÎïÁªÍøÉ豸¡£RealtekJungleSDK°æ±¾v2.xÖÁv3.4.14BÌṩÁËÒ»¸öHTTPWeb·þÎñÆ÷ £¬¹ûÈ»ÁËÒ»¸ö¹ÜÀí½Ó¿Ú £¬¿ÉÓÃÓÚÅäÖýÓÈëµã¡£Õâ¸ö¹ÜÀí½çÃæÓÐÁ½¸ö°æ±¾£ºÒ»¸ö»ùÓÚÃûΪwebsµÄGo-Ahead £¬ÁíÒ»¸ö»ùÓÚÃûΪboaµÄBoa¡£ËüÃǶ¼Êܵ½ÕâЩ©¶´µÄÓ°Ïì¡£

¸üÐÂʱ¼ä£º

20220301

 

ʼþÃû³Æ£º

TCP_Éó¼Æʼþ_JAVA_RMIÇëÇóµ÷ÓÃ

Äþ¾²ÀàÐÍ£º

Äþ¾²Éó¼Æ

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»ú¶ÔÄ¿µÄÖ÷»ú½øÐÐRMIÇëÇó¡£RMI¼´Ô¶³ÌÒªÁìµ÷ÓÃ(RemoteMethodInvocation) £¬Ò»ÖÖÓÃÓÚʵÏÖÔ¶³Ì¹ý³Ìµ÷ÓõÄJavaAPI¡£ÈôÔ´IPÖ÷»ú´æÔÚJAVA·´ÐòÁл¯Â©¶´ £¬¹¥»÷Õß¿ÉÀûÓÃJNDIÀ´µ÷ÓÃRMI £¬¿ÉÄÜ´æÔÚÔ¶³Ì·ÃÎʶñÒ⹤¾ßµÄ·çÏÕ¡£

¸üÐÂʱ¼ä£º

20220301

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_QNAP_RoonServer_ÃüÁî×¢Èë[CVE-2021-28811]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ÍþÁªÍ¨¿Æ¼¼ £¬¼ò³ÆÍþÁªÍ¨ £¬Ó¢ÓïÒëÃûôßÆ·ÅÆÃû³ÆΪQNAP £¬ÊÇ×ܲ¿Î»ÓÚÖйų́ÍåµÄ¿Æ¼¼¹«Ë¾¡£Æä²úÎï°üÂÞÍøÂ總¼Ó´æ´¢É豸¡¢ÊÓƵ¼à¿Ø¼ÏñÉ豸¡¢ÍøÂç½»»»»ú¡¢ÎÞÏß·ÓÉÆ÷¡¢ÎÞÏß/ÓÐÏßÍø¿¨ºÍÊÓƵ»áÒéÉ豸µÈ¡£ÍþÁªÍ¨£¨QNAP£©²úÎïµÄRoonServerÓ¦ÓÃÖÐ £¬´æÔÚȨÏÞÈÏ֤©¶´ÓëÃüÁî×¢È멶´ £¬¹¥»÷Õß¿ÉÒÔ½«Õâ2¸ö©¶´×éºÏÆðÀ´Ê¹Óà £¬ÒÔµ½´ïδÊÚȨԶ³ÌÖ´ÐÐÈÎÒâÃüÁîµÄÄ¿µÄ¡£

¸üÐÂʱ¼ä£º

20220301

 

ʼþÃû³Æ£º

HTTP_ºóÃÅ_BADNEWS_PatchWorkAPT_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ÆäËûʼþ

ʼþÃèÊö£º

¼ì²âµ½patchworkºóÃÅBADNEWSľÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBADNEWSľÂí¡£BADNEWSľÂíÊÇÒ»¸ö¹¦Ð§·Ç³£Ç¿´óµÄºóÃÅ £¬ÔËÐкó £¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£

¸üÐÂʱ¼ä£º

20220301

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Gerapy_clone_Ô¶³ÌÃüÁîÖ´ÐЩ¶´[CVE-2021-32849][CNNVD-202201-2495]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

GerapyÊÇÒ»¿î»ùÓÚScrapy¡¢Scrapyd¡¢DjangoºÍVue.jsµÄÂþÑÜʽÅÀ³æ¹ÜÀí¿ò¼Ü¡£Gerapy0.9.6ºÍ֮ǰµÄ°æ±¾ÖдæÔÚ×¢È멶´ £¬¸Ã©¶´Ô´ÓÚ·¨Ê½Ã»ÓÐÕýÈ·ÇåÀíͨ¹ýproject_clone¶Ëµãͨ±¨¸øPopenµÄÊäÈë £¬µ¼Ö¹¥»÷Õß¿ÉÀûÓø鶴Զ³ÌÖ´ÐÐÈÎÒâÃüÁî¡£

¸üÐÂʱ¼ä£º

20220301

 

ʼþÃû³Æ£º

TCP_ľÂíºóÃÅ_HigaisaRat(ºÚ¸ñɯ)_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½HigaisaRatÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷ £¬Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÔ¶¿ØHigaisaRat¡£HigaisaRatÊÇÒ»¸ö»ùÓÚgh0st¿ªÔ´Ô¶¿Ø¿ò¼ÜÐ޸ĶøÀ´Ô¶³Ì¿ØÖÆľÂí £¬ÔÊÐí¹¥»÷Õß¿ØÖƱ»Ö²Èë»úÆ÷¡£¹¥»÷Õß¿ÉÔ¶³Ì¿ØÖƱ»¿Ø¶ËÖ÷»ú×öÖÖÖÖ²Ù×÷¡£

¸üÐÂʱ¼ä£º

20220301

 

ÐÞ¸Äʼþ

 

ʼþÃû³Æ£º

HTTP_ͨ´ïOA_ÈÎÒâÎļþÉÏ´«/Îļþ°üÂÞ©¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ͨ´ïOAÊÇÒ»Ìװ칫ϵͳ¡£ÓÉÓÚͨ´ïOAÖдæÔÚµÄÁ½Ã¶Â©¶´(ÎļþÉÏ´«Â©¶´ £¬Îļþ°üÂÞ©¶´) £¬¹¥»÷Õß¿Éͨ¹ýÕâÁ½Ã¶Â©¶´ÊµÏÖÔ¶³ÌÃüÁîÖ´ÐС£/ispirit/im/upload.php´æÔÚÈƹýµÇ¼(ÈÎÒâÎļþÉÏ´«Â©¶´) £¬½áºÏgateway.php´¦´æÔÚµÄÎļþ°üÂÞ©¶´ £¬×îÖÕµ¼ÖÂgetshell¡£

¸üÐÂʱ¼ä£º

20220301

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Apache_APISIX_batch-requests_Ô¶³Ì´úÂëÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃApacheAPISIXµÄbatch-requests²å¼þµ÷ÓÃAPI²¢Ö´ÐжñÒâ´úÂë¡£ApacheAPISIXÊÇÒ»¸ö¶¯Ì¬¡¢ÊµÊ±¡¢¸ßÐÔÄܵÄAPIÍø¹Ø¡£APISIXÌṩÁ˸»ºñµÄÁ÷Á¿¹ÜÀíÌØÐÔ £¬ÀýÈ縺Ôؾùºâ¡¢¶¯Ì¬ÉÏÓΡ¢½ð˿ȸÐû²¼¡¢È۶ϡ¢ÈÏÖ¤¡¢¿ÉÊÓ²ìÐԵȡ£

¸üÐÂʱ¼ä£º

20220301