¡¾Îó²îͨ¸æ¡¿Ruckus Wireless AdminÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2023-25717£©

Ðû²¼Ê±¼ä 2023-05-15

Ò»¡¢Îó²î¸ÅÊö

CVE   ID

CVE-2023-25717

·¢Ã÷ʱ¼ä

2023-05-10

Àà    ÐÍ

RCE

µÈ    ¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

¹¥»÷ÖØÆ¯ºó

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

ÊÇ

 

5ÔÂ10ÈÕ£¬£¬£¬£¬c7c7ÓéÀÖÆ½Ì¨VSRC¼à²âµ½FortiGuard LabsÐû²¼Íþвͨ¸æ£¬£¬£¬£¬Åû¶ÁËRuckus Wireless Admin RCEÎó²î£¨CVE-2023-25717£¬£¬£¬£¬CVSSv3ÆÀ·Ö9.8£©ÕýÔÚ±»AndoryuBot½©Ê¬ÍøÂçÆð¾¢Ê¹Ó㬣¬£¬£¬ÒÔÌᳫÂþÑÜʽ¾Ü¾øÐ§ÀÍ£¨DDoS£©¹¥»÷¡£¡£¡£¡£¡£

ÓÅ¿ÆÎÞÏß¹«Ë¾£¨Ruckus Wireless£©ÊÇÒÆ¶¯ÍøÂçÊг¡ÉÏ×ÅÃûµÄÎÞÏßϵͳ¹©Ó¦ÉÌ¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÃæÏòÈ«ÇòÒÆ¶¯ÔËÓªÉÌ¡¢¿í´øÐ§ÀÍÌṩÉÌºÍÆóÒµÓû§£¬£¬£¬£¬ÖÆÔì¡¢ÏúÊÛÖÖÖÖÊÒÄÚºÍÊÒÍâÐÍ¡°ÖÇÄÜWi-Fi¡±²úÆ·¡£¡£¡£¡£¡£

Ruckus Wireless Admin Ãæ°å°æ±¾<=10.4Öб£´æRCE/CSRFÎó²î£¨CVE-2023-25717£©£¬£¬£¬£¬¿ÉÒÔͨ¹ýÏòÒ×Êܹ¥»÷µÄ×°±¸·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄHTTP GETÇëÇóÀ´Ö´ÐдúÂ룬£¬£¬£¬»òʹÓÃCSRFÎó²îÔÚÄ¿µÄ×°±¸ÉÏÖ´ÐдúÂ룬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼Ö¿ØÖÆ»òÆÆËðÒ×Êܹ¥»÷µÄRuckus Wireless AP×°±¸¡£¡£¡£¡£¡£ÏÖÔÚ¸ÃÎó²îµÄPoCÒѾ­¹ûÕæÅû¶¡£¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£

¸ÃÎó²îÓ°ÏìÁËÒÔÏÂRUCKUS APÐͺţ¨²¿·ÖÊÜÓ°Ïì²úÆ·ÒѾ­×èÖ¹Ö§³Ö£©£º

RUCKUS H350

RUCKUS H550

RUCKUS R350

RUCKUS T350c

RUCKUS T350d

RUCKUS T350se

RUCKUS T811-CM (Non-SFP)

Ruckus E510

Ruckus H320

Ruckus H500

Ruckus H510

Ruckus M510

Ruckus M510-JP

Ruckus P300

Ruckus Q410

Ruckus Q710

Ruckus Q910

Ruckus R300

Ruckus R310

Ruckus R320

Ruckus R500

Ruckus R510

Ruckus R550

Ruckus R560

Ruckus R600

Ruckus R610

Ruckus R650

Ruckus R700

Ruckus R710

Ruckus R720

Ruckus R730

Ruckus R750

Ruckus R760

Ruckus R850

Ruckus T300

Ruckus T301n

Ruckus T301s

Ruckus T310c

Ruckus T310d

Ruckus T310n

Ruckus T310s

Ruckus T504

Ruckus T610

Ruckus T710

Ruckus T710s

Ruckus T750

Ruckus T750SE

Ruckus T811-CM

SmartZone 100 (SZ-100)

SmartZone 144 (SZ-144)

SmartZone 144 (SZ-144) - Federal

SmartZone 300 (SZ300)

SmartZone 300 (SZ300) - Federal

ZoneDirector 1000

ZoneDirector 1100

ZoneDirector 1200

ZoneDirector 3000

ZoneDirector 5000

 

Èý¡¢Çå¾²²½·¥

3.1 Éý¼¶°æ±¾

RuckusÒÑÓÚ2ÔÂÐÞ¸´ÐÞ¸´Á˸ÃÎó²î£¬£¬£¬£¬¼øÓÚ¸ÃÎó²îʹÓÃÄѶȽϵÍ£¬£¬£¬£¬ÇÒÎó²îPoCÒѾ­¹ûÕæÅû¶£¬£¬£¬£¬½¨ÒéÈÔδÐÞ¸´¸ÃÎó²îµÄÓû§¿É²Î¿¼¹Ù·½Í¨¸æ»ñÈ¡ÏìÓ¦²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://support.ruckuswireless.com/security_bulletins/315

3.2 ÔÝʱ²½·¥

²»Ê¹ÓÃʱ¿ÉÒÔ½ûÓÃRUCKUS AP×°±¸µÄÔ¶³ÌÖÎÀíÃæ°å»á¼û¡£¡£¡£¡£¡£

3.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£

3.4 ²Î¿¼Á´½Ó

https://support.ruckuswireless.com/security_bulletins/315

https://www.fortiguard.com/threat-signal-report/5151/exploitation-spike-observed-for-ruckus-wireless-admin-rce-vulnerability-cve-2023-25717

https://cybir.com/2023/cve/proof-of-concept-ruckus-wireless-admin-10-4-unauthenticated-remote-code-execution-csrf-ssrf/

https://www.bleepingcomputer.com/news/security/critical-ruckus-rce-flaw-exploited-by-new-ddos-botnet-malware/

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-05-15

Ê×´ÎÐû²¼

  

Îå¡¢¸½Â¼

5.1 c7c7ÓéÀÖÆ½Ì¨¼ò½é

c7c7ÓéÀÖÆ½Ì¨½¨ÉèÓÚ1996Ä꣬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°c7c7ÓéÀÖÆ½Ì¨´óÏ㬣¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬£¬£¬c7c7ÓéÀÖÆ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£

5.2 ¹ØÓÚc7c7ÓéÀÖÆ½Ì¨

c7c7ÓéÀÖÆ½Ì¨Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£¡£¡£

¹Ø×¢ÎÒÃÇ£º

image.png