¡¾Â©¶´Í¨¸æ¡¿»ªË¶Â·ÓÉÆ÷¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2023-06-20

Ò»¡¢Â©¶´¸ÅÊö

2023Äê6ÔÂ20ÈÕ £¬¶«É­Æ½Ì¨VSRC¼à²âµ½»ªË¶£¨ASUS£©Ðû²¼ÁËÆä¶à¿î·ÓÉÆ÷ÐͺŵĹ̼þÀÛ»ýÄþ¾²¸üР£¬ÐÞ¸´Á˶à¿î»ªË¶Â·ÓÉÆ÷ÐͺÅÖеĶà¸öÄþ¾²Â©¶´ £¬ÈçÏ£º

CVE-2023-28702£º»ªË¶Â·ÓÉÆ÷ÃüÁî×¢Èë©¶´£¨¸ßΣ£©

»ªË¶ RT-AC86U ûÓйýÂËÌØ¶¨ÍøÒ³URLÖвÎÊýµÄÌØÊâ×Ö·û £¬µÍȨÏÞÓû§¿ÉÔ¶³ÌÀûÓøÃ©¶´½øÐÐÃüÁî×¢Èë¹¥»÷ £¬Ö´ÐÐÈÎÒâϵͳÃüÁî £¬µ¼ÖÂϵͳÖжϻòÖÕÖ¹·þÎñµÈ¡£

CVE-2023-28703£º»ªË¶Â·ÓÉÆ÷»º³åÇøÒç³ö©¶´£¨¸ßΣ£©

»ªË¶RT-AC86UµÄÌØ¶¨cgi¹¦Ð§ÓÉÓÚ¶ÔÍøÂç°üÍ·³¤¶ÈÑéÖ¤²»×ã £¬µ¼Ö´æÔÚ»ùÓÚ¶ÑÕ»µÄ»º³åÇøÒç³ö©¶´ £¬¾ßÓйÜÀíԱȨÏÞµÄÔ¶³ÌÍþвÕß¿ÉÀûÓøÃ©¶´Ö´ÐÐÈÎÒâϵͳÃüÁî¡£

CVE-2023-31195£º»ªË¶Â·ÓÉÆ÷»á»°½Ù³Ö©¶´£¨ÖÐΣ£©

»ªË¶Â·ÓÉÆ÷RT-AX3000¹Ì¼þ°æ±¾3.0.0.4.388.23403֮ǰ £¬Ê¹Óò»´ø'Secure'ÊôÐÔµÄÃô¸Ðcookies¡£µ±ÍþвÕßÄܹ»ÌᳫÖмäÈ˹¥»÷ £¬¶øÇÒÓû§±»ÓÕÆ­Í¨¹ýδ¼ÓÃÜ£¨'http'£©Á¬½ÓµÇ¼µ½ÊÜÓ°ÏìµÄÉ豸ʱ £¬Óû§µÄ»á»°¿ÉÄܻᱻ½Ù³Ö¡£

CVE-2022-38105£º»ªË¶Â·ÓÉÆ÷ÐÅϢй¶©¶´£¨¸ßΣ£©

»ªË¶RT-AX82U 3.0.0.4.386_49674-ge182230·ÓÉÆ÷ÅäÖ÷þÎñµÄcm_processREQ_NC²Ù×÷Âë´æÔÚÐÅϢй¶©¶´ £¬¿ÉÒÔͨ¹ýÌØÖÆµÄÍøÂçÊý¾Ý°üµ¼ÖÂÃô¸ÐÐÅϢй¶¡£

CVE-2022-35401£º»ªË¶Â·ÓÉÆ÷Éí·ÝÑéÖ¤ÈÆ¹ý©¶´£¨ÑÏÖØ£©

»ªË¶ RT-AX82U 3.0.0.4.386_49674-ge182230 µÄ get_IFTTTTtoken.cgi ¹¦Ð§ÖдæÔÚÉí·ÝÑéÖ¤ÈÆ¹ý©¶´ £¬¿ÉÒÔͨ¹ýÌØÖÆµÄ HTTP ÇëÇóÀûÓøÃ©¶´ £¬ÀÖ³ÉÀûÓÿÉÄÜ»ñµÃ¶ÔÉ豸µÄÍêÈ«¹ÜÀí·ÃÎÊ¡£

CVE-2022-38393£º»ªË¶Â·ÓÉÆ÷¾Ü¾ø·þÎñ©¶´£¨¸ßΣ£©

»ªË¶RT-AX82U 3.0.0.4.386_49674-ge182230·ÓÉÆ÷ÅäÖ÷þÎñµÄcfg_server cm_processConnDiagPktList²Ù×÷Âë´æÔھܾø·þÎñ©¶´ £¬¿ÉÒÔͨ¹ý·¢ËͶñÒâÊý¾Ý°üµ¼Ö¾ܾø·þÎñ¡£

CVE-2022-26376£º»ªË¶Â·ÓÉÆ÷ÄÚ´æËð»µÂ©¶´£¨ÑÏÖØ£©

Asuswrt°æ±¾3.0.0.4.386_48706֮ǰ¡¢Asuswrt-Merlin New Gen°æ±¾386.7֮ǰµÄhttpd unescape¹¦Ð§ÖдæÔÚÄÚ´æËð»µÂ©¶´ £¬¿ÉÒÔͨ¹ý·¢ËÍÌØÖÆHTTPÇëÇóÀ´ÀûÓøÃ©¶´ £¬ÀÖ³ÉÀûÓÿÉÄܵ¼Ö¾ܾø·þÎñ»ò´úÂëÖ´ÐС£

´ËÍâ £¬»ªË¶±¾´ÎÐû²¼µÄ¹Ì¼þÀÛ»ýÄþ¾²¸üл¹ÐÞ¸´Á˹ýʱµÄ¿âlibusrsctpÖеÄ©¶´£¨CVE-2022-46871 £¬¸ßΣ£©£»ÒÔ¼°NetatalkÔ½½çдÈë©¶´£¨CVE-2018-1160 £¬ÑÏÖØ£© £¬Netatalk°æ±¾3.1.12֮ǰÔÚdsi_opensess.cÖдæÔÚÔ½½çдÈë©¶´ £¬ÓÉÓÚȱ·¦¶ÔÍþвÕß¿ØÖƵÄÊý¾ÝµÄ½çÏÞ¼ì²é £¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕß¿ÉÀûÓøÃ©¶´ÊµÏÖÈÎÒâ´úÂëÖ´ÐС£

 

¶þ¡¢Ó°Ï췶Χ

ÊÜÓ°ÏìµÄÉ豸ÐͺŰüÂÞ£º

GT6

GT-AXE16000

GT-AX11000 PRO

GT-AX6000

GT-AX11000

GS-AX5400

GS-AX3000

XT9

XT8

XT8 V2

RT-AX86U PRO

RT -AX86U

RT-AX86S

RT-AX82U

RT-AX58U

RT-AX3000

TUF-AX6000

TUF-AX5400

 

Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ»ªË¶ÒѾ­Ðû²¼ÁËÊÜÓ°ÏìÉ豸ÐͺŵĹ̼þÄþ¾²¸üР£¬ÊÜÓ°ÏìÓû§¿É¸üе½×îй̼þ°æ±¾¡£

ÏÂÔØÁ´½Ó£º

https://www.asus.com/support/

3.2 ÁÙʱ´ëÊ©

Èç¹û²»Äܼ°Ê±°²×°ÐµĹ̼þ°æ±¾ £¬½¨Òé½ûÓÿɴÓWAN¶Ë·ÃÎʵķþÎñ £¬ÒÔ¼õÉÙ¹¥»÷Ãæ¡£ÕâЩ·þÎñ°üÂÞ´ÓWANÔ¶³Ì·ÃÎÊ¡¢¶Ë¿Úת·¢¡¢DDNS¡¢VPN·þÎñÆ÷¡¢DMZ¡¢¶Ë¿Ú´¥·¢Æ÷µÈ¡£

¸ü¶àÄþ¾²ÉèÖÿɲο¼£º

https://www.asus.com/support/FAQ/1008000

https://www.asus.com/support/FAQ/1039292

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡ £¬¼õÉÙϵͳ©¶´ £¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ £¬Ð޸ķÀ»ðǽ¼ÆÄ± £¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ £¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø £¬¼õÉÙ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎï £¬ÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí £¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò £¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://www.asus.com/content/asus-product-security-advisory/

https://www.bleepingcomputer.com/news/security/asus-urges-customers-to-patch-critical-router-vulnerabilities/

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-06-20

Ê×´ÎÐû²¼

 

Îå¡¢¸½Â¼

5.1 ¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨½¨Á¢ÓÚ1996Äê £¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«É­Æ½Ì¨´óÏà £¬¹«Ë¾Ô±¹¤6000ÓàÈË £¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö £¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´ £¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ £¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

5.2 ¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯ £¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´ £¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png