Davolink DVW-3200N·ÓÉÆ÷¸ßΣÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-08-02

Îó²î±àºÅºÍ¼¶±ð


CVE-2018-10618  ³§ÉÌ×ÔÆÀ£º9.8   CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾£º


DVW-3200N version < 1.00.06


²»ÊÜÓ°ÏìµÄ°æ±¾£º


DVW-3200N version 1.00.06


Îó²î¸ÅÊö


7ÔÂ31ÈÕ  £¬Davolink DVW-3200N ·ÓÉÆ÷±»ÆØ³ö1¸ö¸ßΣÎó²î£¨CVE-2018-10618£© ¡£¸Ã·ÓÉÆ÷ÌìÉúÈÝÒ×±»ÆÆ½âµÄÈõÃÜÂë  £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß»ñȡװ±¸µÄÃÜÂë ¡£


Davolink DVW-3200N ·ÓÉÆ÷µÄ¶Ë¿Ú88ÉÏÓеǼÃÅ»§  £¬»á¼ûÊÜÃÜÂë±£»¤  £¬µ«ÃÜÂëÔÚµÇÂ¼Ò³ÃæµÄHTMLÖÐÊÇÓ²±àÂëµÄ ¡£ÆÊÎöÒ³Ãæ´úÂë  £¬Ò»¸öÃûΪ¡°clickApply¡±µÄº¯Êý  £¬ÆäÖаüÀ¨±ê×¼base 64±àÂëÖеÄÃÜÂë ¡£


Îó²îʹÓÃ


Îó²îʹÓôúÂ룺https://cxsecurity.com/issue/WLB-2018070219 ¡£


ÐÞ¸´½¨Òé


Davolink¹Ù·½Îª¸Ã×°±¸ÌṩÁËÒ»¸öеĹ̼þ°æ±¾  £¬¿ÉÒÔ´ÓÒÔÏÂÁ´½ÓÏÂÔØ£ºhttp://www.davolink.co.kr/sys/bbs/board.php?bo_table=0403&wr_id=50 ¡£


²Î¿¼Á´½Ó


http://www.davolink.co.kr/sys/bbs/board.php?bo_table=0403&wr_id=50


https://ics-cert.us-cert.gov/advisories/ICSA-18-212-01


https://cxsecurity.com/issue/WLB-2018070219