Realtek Wi-Fi¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-02-07

0x00 Îó²î¸ÅÊö

Realtek RTL8195AMÊÇÒ»¿î¸ß¶È¼¯³ÉµÄµ¥Ð¾Æ¬£¬£¬ £¬£¬¾ßÓе͹¦ºÄ»úÖÆ£¬£¬ £¬£¬ºÜÊÇÊʺÏÓ¦ÓÃÓÚIoT£¨ÎïÁªÍø£©¡£¡£¡£¡£¡£

2021Äê02ÔÂ06ÈÕ£¬£¬ £¬£¬ÒÔÉ«ÁÐÎïÁªÍøÇå¾²¹«Ë¾VdooµÄÑо¿Ö°Ô±Åû¶ÁËÔÚRealtek RTL8195A Wi-FiÄ£¿£¿£¿ £¿£¿£¿éÖз¢Ã÷µÄ6¸öÇå¾²Îó²î£¬£¬ £¬£¬¹¥»÷ÕßÄܹ»Ê¹ÓÃÕâЩÎó²îÀ´»ñµÃrootÓû§µÄ»á¼ûȨÏÞ²¢¿ØÖÆ×°±¸µÄÎÞÏßͨѶ¡£¡£¡£¡£¡£Ö»¹ÜÏÖÔÚÕâЩÎó²îÒѱ»ÐÞ¸´£¬£¬ £¬£¬µ«Ê¹ÓÃRealtek RTL8195A Wi-FiÄ£¿£¿£¿ £¿£¿£¿éµÄǶÈëʽװ±¸½«Ì»Â¶ÔÚÔ¶³Ì¹¥»÷µÄΣº¦ÖС£¡£¡£¡£¡£

0x01 Îó²îÏêÇé

image.png

 

RTL8195A оƬ֧³ÖWEP¡¢WPAºÍWPA2Éí·ÝÑé֤ģʽ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬ £¬£¬ Wi-FiÄ£¿£¿£¿ £¿£¿£¿éµÄWPA2ËÄ´ÎÎÕÊÖ»úÖÆÔÚÈÏ֤ʱÈÝÒ×±£´æ¿ÍÕ»Òç³öºÍÔ½½ç¶ÁÈ¡ÎÊÌâ¡£¡£¡£¡£¡£

±ðµÄ£¬£¬ £¬£¬´Ë´Î·¢Ã÷µÄÎó²î»¹»áÓ°ÏìÆäËüÄ£¿£¿£¿ £¿£¿£¿é£¬£¬ £¬£¬ÈçRTL8711AM¡¢RTL8711AFºÍRTL8710AF¡£¡£¡£¡£¡£ÆäÖÐ×îÑÏÖØµÄÊÇÒ»¸ö¿ÍÕ»Òç³öÎó²î£¨¸ú×ÙΪCVE-2020-9395£©£¬£¬ £¬£¬Ëü¿ÉÄܵ¼ÖÂ×°±¸ºÍÄ£¿£¿£¿ £¿£¿£¿éµÄͨѶÍêÈ«±»¿ØÖÆ¡£¡£¡£¡£¡£¸ÃÎó²îÎÞÐèÖªµÀWi-FiÍøÂçÃÜÂ루PSK£©Ò²¿É±»Ê¹Óᣡ£¡£¡£¡£

ÔÚÎÞÐèÖªµÀWi-FiÍøÂçÃÜÂ루PSK£©µÄÇéÐÎÏ£¬£¬ £¬£¬¹¥»÷ÕßÒ²¿ÉÒÔͨ¹ýʹÓÃCVE-2020-25853ºÍCVE-2020-25857µ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£ÈôÊǹ¥»÷ÕßÖªµÀÍøÂçµÄPSK£¬£¬ £¬£¬Ôò¿ÉÒÔͨ¹ýʹÓÃCVE-2020-25854¡¢CVE-2020-25855ºÍCVE-2020-25856Ô¶³ÌÖ´ÐдúÂë»òµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£

±¾´ÎÅû¶µÄÎó²îÈçÏ£º

²úÆ·

CVE

ÀàÐÍ

ÆÀ¼¶

Ó°Ïì¹æÄ£

Realtek   RTL8195AM¡¢RTL8711A¡¢RTL8711AFºÍRTL8710AF

CVE-2020-9395

»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³ö

¸ßΣ

< 2.0.6

Realtek   RTL8195A Wi-FiÄ£¿£¿£¿ £¿£¿£¿é

CVE-2020-25853

Ô½½ç¶ÁÈ¡

ÖÐΣ

< 2.0.8

CVE-2020-25854

»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³ö

CVE-2020-25855

CVE-2020-25856

CVE-2020-25857

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚÏà¹ØÎó²îÒѱ»ÐÞ¸´£¬£¬ £¬£¬½¨ÒéÉý¼¶ÖÁ2.0.8»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://github.com/ambiot/amb1_arduino

 

0x03 ²Î¿¼Á´½Ó

https://www.realtek.com/en/products/communications-network-ics/item/rtl8195am

https://securityaffairs.co/wordpress/114280/security/realtek-rtl8195a-flaws.html?

https://www.amebaiot.com/en/ameba-arduino-getting-started/

https://nvd.nist.gov/vuln/detail/CVE-2020-9395

 

0x04 ʱ¼äÏß

2021-02-06  Vdoo¹ûÕæÅû¶Îó²î

2021-02-07  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png