Telestar TelnetºóÃÅÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-09-10¡ñÎó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-13473£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-13474£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
¡ñÓ°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
Bobs Rock Radio
Dabman D10
Dabman i30 Stereo
Imperial i110
Imperial i150
Imperial i200
Imperial i200-cd
Imperial i400
Imperial i450
Imperial i500-bt
Imperial i600
¡ñÎó²î¸ÅÊö
½üÆÚ£¬£¬£¬£¬£¬£¬£¬£¬ÓÐÇå¾²Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬£¬£¬ImperialºÍDabmanϵÁеÄÎïÁªÍøÊÕÒô»ú±£´æÈõÃÜÂëȱÏÝ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÈù¥»÷ÕßÔ¶³ÌÒÔrootȨÏÞ¾ÙÐв»·¨»á¼û£¨¸Ã×°±¸ÄÚǶLinux BusyBox²Ù×÷ϵͳ£©£¬£¬£¬£¬£¬£¬£¬£¬²¢ÍêÈ«¿ØÖÆ×°±¸¡£¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߿ɰÑÒÑ¿ØÖÆ×°±¸¼ÓÈë½©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬£¬£¬Ïò×°±¸·¢ËÍ×Ô½ç˵ÒôƵÁ÷£¬£¬£¬£¬£¬£¬£¬£¬¼àÌýËùÓÐÊÕÒô»úÐÂÎÅ£¬£¬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔÕÒµ½ÊÕÒô»úÒÑÅþÁ¬WiFiµÄÃÜÂë¡£¡£¡£¡£¡£¡£¡£
CVE-2019-13473
¸ÃÎó²îÉæ¼°ÊÕÒô»úÉÏ23¶Ë¿ÚµÄTelnetЧÀÍ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ¸ÃTelnetdЧÀÍʹÓÃÁËÈõÃÜÂ루Ӳ±àÂëÔÚ×°±¸ÖУ©£¬£¬£¬£¬£¬£¬£¬£¬Ö»ÒªÍ¨¹ý¼òÆÓµÄÃÜÂ뱩Á¦ÆÆ½â£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߾ͿɻñµÃ¶ÔÊÕÒô»ú¼°ÆäÄÚǶ²Ù×÷ϵͳµÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£
ÔÚ²âÊÔÖУ¬£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬Ö»ÒªÊ¹ÓÃ×Ô¶¯µÄ¡°ncrack¡±¾ç±¾£¬£¬£¬£¬£¬£¬£¬£¬Ê®·ÖÖÓÄÚ¾Í¿ÉÆÆ½âÃÜÂë¡£¡£¡£¡£¡£¡£¡£ÖµµÃÒ»ÌáµÄÊÇ£¬£¬£¬£¬£¬£¬£¬£¬×°±¸µÄÓ²±àÂëÃÜÂëΪ¡°password¡±¡£¡£¡£¡£¡£¡£¡£
ÔڵǼµ½×°±¸ºó,Ñо¿Ö°Ô±Äܹ»Ö±½Ó»á¼ûetcĿ¼ÏÂÐèÒªrootÌØÈ¨²Å»ª»á¼ûµÄÖÖÖÖÎļþ£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨º¬ÓÐϵͳÃÜÂëµÄshadowÎļþ£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨USBÃÜÂëºÍhttpdЧÀÍÃÜÂëµÄwifi.cfgÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÉÐÓÐһЩÃô¸ÐµÄÎÞÏßÍøÂçÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
ƾ֤Çå¾²Ñо¿Ö°Ô±ÖÜÒ»Ðû²¼µÄÒ»·Ý±¨¸æ£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚΪֹ£¬£¬£¬£¬£¬£¬£¬£¬ËûÃÇÄܹ»»á¼ûºÍhttpd¡¢TelnetÓйصÄËùÓÐÎļþ£¬£¬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔ¼¤»îftpÐÒé¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±»¹·¢Ã÷ÁËÒ»¸öÃûΪUIDataµÄ·¾¶£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨×°±¸webЧÀÍ£¨¿ª·ÅÔÚ80¶Ë¿ÚºÍ8080¶Ë¿Ú£©µÄËùÓÐÎļþ(¶þ½øÖÆÎļþ¡¢xml¡¢Í¼Æ¬¡¢Îı¾ºÍÆäËûÄÚÈÝ)¡£¡£¡£¡£¡£¡£¡£ÎªÁ˾ÙÐвâÊÔ£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃDZà¼ÁËһЩÎļþ¼Ð¡¢½¨ÉèÁËÎļþ²¢ÐÞ¸ÄÁË·¾¶£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ±ã²âÊÔÎÒÃÇÊÇ·ñÄܸıäwebЧÀ͵ÄÔ´´úÂë¡£¡£¡£¡£¡£¡£¡£×îÖÕ֤ʵÎúÎÒÃÇÄܹ»ÍêÈ«¿ØÖÆ×°±¸µÄÈκÎ×é¼þºÍЧÀÍ¡£¡£¡£¡£¡£¡£¡£
CVE-2019-13474
AirMusic¿Í»§¶Ë±£´æµÚ¶þ¸öÎó²î(CVE-2019-13474)£¬£¬£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÏÂÁîÖ´ÐС£¡£¡£¡£¡£¡£¡£
Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÆ»¹ûIOSÉϵÄÊÕÒô»úÓ¦Ó㬣¬£¬£¬£¬£¬£¬£¬Á¬Ïµ¶Ë¿ÚɨÃèЧ¹û£¬£¬£¬£¬£¬£¬£¬£¬·¢Ã÷AirMusic¿Í»§¶Ë¿ÉÄÜͨ¹ý80ºÍ8080¶Ë¿ÚµÄhttpdЧÀÍÀ´·¢ËͺÍÎüÊÕÏÂÁî¡£¡£¡£¡£¡£¡£¡£¾ÓÉÒ»¸öСʱµÄ²âÊÔ£¬£¬£¬£¬£¬£¬£¬£¬×îÖÕÑо¿Ö°Ô±È·¶¨Äܹ»Í¨¹ýwebЧÀÍÏò¿Í»§¶Ë·¢ËÍÏÂÁî¡£¡£¡£¡£¡£¡£¡£
ÒÔÉÏÕâÁ½¸öÎó²îÒ»µ©×éºÏÆðÀ´£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜ»áÒý·¢Ò»ÏµÁжñÒâÍøÂç»î¶¯¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ¼àÌý¡¢¸ü¸Ä¹ã²¥Á÷»ò·¢ËÍ×Ô¼ºµÄʵʱÐÂÎÅ»òÒôƵÎļþ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹¿É°Ñ×°±¸Ë¢Ð³ɽ©Ê¬ÍøÂçÖеÄÒ»Ô±£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃËüµÄwebЧÀÍת´ïÀÕË÷Èí¼þºÍ¶ñÒⲡ¶¾¡£¡£¡£¡£¡£¡£¡£
Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩÎó²î¡°Ó°ÏìÁËImperialºÍDabmanÆ·ÅÆµÄ´ó×ÚÍøÂçÊÕÒô»ú¡±¡£¡£¡£¡£¡£¡£¡£ËûÃÇÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÓÐ100¶àÍǫ̀װ±¸´¦ÓÚΣÏÕÖ®ÖС£¡£¡£¡£¡£¡£¡£ÏÖÔÚÕâЩÊÕÒô»úÓÉTelestar Digital GmbHÔڵ¹úÏúÊÛ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚÑÇÂíÑ·(Amazon)ºÍeBayÉÏÃæÁÙÈ«Çò¾ÙÐÐÏúÊÛ£¬£¬£¬£¬£¬£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚ¼ÒÍ¥ºÍ°ì¹«ÇéÐΡ£¡£¡£¡£¡£¡£¡£TelstarÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔºó×°±¸½«×èֹʹÓÃTelnetЧÀÍ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÎªÏÖÓÐ×°±¸Ðû²¼Çå¾²²¹¶¡¡£¡£¡£¡£¡£¡£¡£
¡ñÎó²îÑéÖ¤
POC£ºhttps://www.vulnerability-lab.com/get_content.php?id=2183
POCÊÓÆµ£ºhttps://youtu.be/odyB15MRY3Q¡£¡£¡£¡£¡£¡£¡£
¡ñÐÞ¸´½¨Òé
ÖÆÔìÉÌtelestar digital gmbhÌṩÁËÒ»¸öȫеĸüа汾£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ½â¾öÆäÖеÄÎó²î¡£¡£¡£¡£¡£¡£¡£ËùÓÐi&dϵÁвúÆ·¡£¡£¡£¡£¡£¡£¡£½¨Ò龡¿ì×°ÖøüÐÂÒÔÈ·±£Êý×ÖÇå¾²¡£¡£¡£¡£¡£¡£¡£
ÊÖ¶¯¸üа취£º
1.½«×°±¸ÉèÖÃΪ³ö³§ÉèÖÃ
2.Ñ¡ÔñÓïÑÔ
3.¹Ø±Õ×°±¸
4.·¿ª×°±¸
5.ÍøÂçÉèÖÃ
6.ÆÚ´ý¡°ÐÂÈí¼þ¡±ÐÂÎÅ
7.°´¡°È·¶¨¡±×îÏȸüÐÂ
8.¸üа汾£ºTN81HH96-g102h-g103 ** a * -fb21a-3624¡£¡£¡£¡£¡£¡£¡£
¡ñ²Î¿¼Á´½Ó
https://www.zdnet.com/article/critical-vulnerabilities-impact-over-a-million-iot-radio-devices/


¾©¹«Íø°²±¸11010802024551ºÅ