CDATA OLTsÖжà¸ö0dayÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-07-08
0x00 Îó²î¼ò½é
2020Äê7ÔÂ7ÈÕ,Ñо¿Ö°Ô±PierreÅû¶ÁËCDATA OLTÖб£´æµÄ¶à¸ö0dayÎó²î£¬£¬£¬¶Ô²úÆ·µÄ¶à¸ö°æ±¾¶¼ÓÐÓ°Ïì¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪÕâЩºóÃÅÓ¦ÊÇCDATA¾ÓÐÄ¿ª·¢µÄ£¬£¬£¬Òò´ËÅû¶Îó²îµÄËùÓÐϸ½Ú£¬£¬£¬ÕâЩÎó²îµÄCVEÔÝδ·ÖÅÉ¡£¡£¡£¡£¡£¡£¡£
CDATA OLTÊÇOEM FTTH OLT£¬£¬£¬Éæ¼°Cdata¡¢OptiLink¡¢V-SOL CNºÍBLIYµÈÆ·ÅÆ¡£¡£¡£¡£¡£¡£¡£Ò»Ð©×°±¸Ö§³Ö¶à¸ö10 GbÉÏÐÐÁ´Â·£¬£¬£¬²¢Ìṩ¶à´ï1024¸öONT£¨¿Í»§¶Ë£©µÄInternetÅþÁ¬¡£¡£¡£¡£¡£¡£¡£
FTTH£¨Fiber To The Home£©£¬£¬£¬¼´¹âÏ˵½»§ÊÇÖ¸½«¹âÍøÂ絥루ONU£©×°ÖÃÔÚס¼ÒÓû§»òÆóÒµÓû§´¦£¬£¬£¬Êǹâ½ÓÈëϵÁÐÖÐ×î¿¿½üÓû§µÄ¹â½ÓÈëÍøÓ¦ÓÃÀàÐÍ¡£¡£¡£¡£¡£¡£¡£FTTHµÄ¹âÏ˽ÓÈëÊÖÒÕÓÐÐí¶àÖÖ£¬£¬£¬ÆäÖÐÒ»ÖÖÊÇGPON¡£¡£¡£¡£¡£¡£¡£GPON FTTHºÜÊÇÊ¢ÐУ¬£¬£¬ÓÉÓÚËü¼ÛÇ®×ÔÖÆ£¬£¬£¬²¢ÇÒÔÊÐíÈËÃÇ¿ìËÙÏÂÔØÕýµ±µÄÊÓÆµµã²¥¡£¡£¡£¡£¡£¡£¡£
Ñо¿Ö°Ô±Ê¹ÓÃ×îй̼þ°æ±¾£¨V1.2.2ºÍ2.4.05_000¡¢2.4.04_001ºÍ2.4.03_000£©ÔÚʵÑéÊÒÇéÐÎÖÐÑéÖ¤ÁËÕë¶ÔFD1104BºÍFD1108SN OLTµÄÎó²î¡£¡£¡£¡£¡£¡£¡£
ͨ¹ý¾²Ì¬ÆÊÎö£¬£¬£¬ÕâЩÎó²îËÆºõÒ²»áÓ°ÏìËùÓпÉÓõÄOLTÄ£×Ó£¬£¬£¬ÓÉÓÚ´úÂë¿âÀàËÆ£º
? 72408A
? 9008A
? 9016A
? 92408A
? 92416A
? 9288
? 97016
? 97024P
? 97028P
? 97042P
? 97084P
? 97168P
? FD1002S
? FD1104
? FD1104B
? FD1104S
? FD1104SN
? FD1108S
? FD1204S-R2
? FD1204SN
? FD1204SN-R2
? FD1208S-R2
? FD1216S-R1
? FD1608GS
? FD1608SN
? FD1616GS
? FD1616SN
? FD8000
´ÓÆÊÎöµÄ¶þ½øÖÆÎļþÖУ¬£¬£¬ÎÒÃÇÌáÈ¡ÁËÓйØOEMÊðÀíÉ̵ÄÐÅÏ¢£º
´ÓͼÖпÉÒÔ¿´µ½£¬£¬£¬¸ÃÊðÀíÉÌΪÎ÷µÏÌØ£¨CDATA£©£¬£¬£¬ÉîÛÚÊÐÎ÷µÏÌØ¿Æ¼¼ÓÐÏÞ¹«Ë¾ÊÇÒ»¼ÒרעÓÚÌṩ¿í´øÍøÂç½ÓÈë×°±¸µÄ¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£¡£¡£¹«Ë¾µÄÖ÷Òª²úÆ·°üÀ¨GPON¡¢EPONÍøÂç×°±¸¡¢EOCÍøÂç×°±¸¡¢CATV¹â´«Êä×°±¸¡£¡£¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé
´Ë´Î·¢Ã÷µÄÎó²î°üÀ¨telnetºóÃÅ¡¢Æ¾Ö¤ÐÅÏ¢×ß©ºÍÃ÷ÎÄÃûÌÃÆ¾Ö¤£¨telnet£©¡¢¾ßÓÐrootÌØÈ¨µÄEscape Shell¡¢Ô¤Éí·ÝÑéÖ¤Ô¶³ÌDoS¡¢Æ¾Ö¤ÐÅÏ¢×ß©ºÍÃ÷ÎÄÆ¾Ö¤£¨HTTP£©¡¢Èõ¼ÓÃÜËã·¨ºÍÖÎÀí½çÃæ²»Çå¾²£¬£¬£¬ÏÂÃæ¾ÙÐÐÏêϸÏÈÈÝ¡£¡£¡£¡£¡£¡£¡£
1. telnetºóÃÅ
¹¥»÷Õß¿ÉÒÔ´ÓWAN½Ó¿ÚºÍFTTH LAN½Ó¿Ú»á¼ûtelnetЧÀÍ£¬£¬£¬»ñµÃÖÎÀíÔ±CLI»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£²î±ðµÄ¹Ì¼þÓвî±ðµÄÓ²±àÂëºóÃÅÆ¾Ö¤£¬£¬£¬²Î¿¼ÈçÏ£º
ÒÔǰµÄ°æ±¾¿ÉÒÔͨ¹ýÒÔÏ·½·¨µÇ¼£º
login: suma123¡£¡£¡£¡£¡£¡£¡£
password: panger123
×îеÄа汾¿ÉÒÔͨ¹ýÒÔÏ·½·¨µÇ¼£º
login: debug
password: debug124
login: root
password: root126
login: guest
password: [empty]
ƾ֤ÒÑÖØÐ¾ɹ̼þÓ³ÏñÖÐÌáÈ¡¡£¡£¡£¡£¡£¡£¡£
ƾ֤²î±ðµÄ¹©Ó¦É̺͹̼þ°æ±¾£¬£¬£¬CLIµÄÍâ¹Û¿ÉÄÜÓÐËù²î±ð£¬£¬£¬µ«»á¼ûÈÔÈ»ÓÐÓᣡ£¡£¡£¡£¡£¡£
ʹÓÃsuma123/panger123£º
ʹÓÃguest/[empty]£º
ʹÓÃroot/root126£º
ʹÓÃdebug/debug124£º
ÓÐÁËÕâЩ»á¼ûȨÏÞ£¬£¬£¬¹¥»÷Õ߾ͿÉÒÔ¶Ô²úÆ·¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£
2. ƾ֤ÐÅÏ¢×ß©ºÍÃ÷ÎÄÃûÌÃÆ¾Ö¤£¨telnet£©
ÎÒÃǼÙÉè¹¥»÷ÕßÒѾ¾ßÓÐCLI»á¼ûȨÏÞ£¨¿ÉÒÔͨ¹ýʹÓÃtelnetµÄBackdoor»á¼ûÀ´ÊµÏÖ£©¡£¡£¡£¡£¡£¡£¡£
¹¥»÷Õß¿ÉÔÚCLIÖÐÔËÐÐÏÂÁî»ñÈ¡ÖÎÀíԱƾ֤£º
3. ¾ßÓÐrootÌØÈ¨µÄEscape Shell
ÎÒÃǼÙÉè¹¥»÷Õß¾ßÓÐCLI»á¼ûȨÏÞ£¨¿ÉÒÔͨ¹ýʹÓÃtelnetµÄBackdoor»á¼ûÀ´ÊµÏÖ£©¡£¡£¡£¡£¡£¡£¡£
CLIÖÐÓÐÏÂÁî×¢È빦Ч£¬£¬£¬¹¥»÷Õß¿ÉÒÔÒÔrootȨÏÞÖ´ÐÐÏÂÁî¡£¡£¡£¡£¡£¡£¡£
ÏÂÁî×¢ÈëλÓÚTFTPÏÂÔØÉèÖò¿·Ö¡£¡£¡£¡£¡£¡£¡£
ÎÒÃÇʹÓÃmetasploitÔÚ192.168.1.101ÉÏÆô¶¯TFTPЧÀÍÆ÷£¬£¬£¬²¢ÎüÊÕ×¢ÈëÏÂÁ£¬£¬Ð§¹ûÈçÏ£º
ÔÚOLTÉÏ£º
ÔÚ¹¥»÷ÕßÅÌËã»úÉÏÔËÐеÄTFTPЧÀÍÆ÷ÉÏ£¬£¬£¬ÎÒÃÇÊÕµ½ÏÂÁîµÄÊä³öcat /proc/cpuinfo£º
Ò²¿ÉÒÔʹÓÃǶÈëʽWebЧÀÍÆ÷À´Ð¹Â¶ÐÅÏ¢£º
ÔÚOLTÉÏ£º
ÔÚ¹¥»÷Õß»úеÉÏ£º
±ðµÄ£¬£¬£¬ÉÐÓÐÐí¶àÏÂÁî¶¼¿ÉÒÔÒÔrootȨÏÞÖ´ÐУ¬£¬£¬ÏêϸÈçÏ£º
4. Ô¤Éí·ÝÑéÖ¤Ô¶³ÌDoS
¹¥»÷Õß¿ÉÒÔ´ÓWAN½Ó¿ÚºÍFTTH LAN½Ó¿Ú»á¼ûtelnetЧÀÍ£¬£¬£¬Ê¹ÓûùÓÚIA¡¢»úеѧϰºÍshawarmaµÄÄ£ºýÊÖÒÕ£¬£¬£¬ÖØÆôËùÓÐOLT¡£¡£¡£¡£¡£¡£¡£
×°±¸½«ÔÚ½ÓÏÂÀ´µÄ5ÃëÖÓÄÚÖØÆô£¬£¬£¬ËùÓеÄLED¶¼½«ÏñÊ¥µ®Ê÷Ò»ÑùÉÁׯ¡£¡£¡£¡£¡£¡£¡£
5. ƾ֤ÐÅÏ¢×ß©ºÍÃ÷ÎÄÆ¾Ö¤£¨HTTP£©
¹¥»÷Õß¿ÉÒÔ´ÓWAN½Ó¿ÚºÍFTTH LAN½Ó¿Ú»á¼ûwebЧÀÍÆ÷£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý»ñÈ¡ÒÔÏÂÎļþÀ´ÌáÈ¡Web£¬£¬£¬Telnetƾ֤ºÍSNMPÉçÇø×Ö·û´®£¨¶Áд£©£º
ʹÓÃcurl£º
6. Èõ¼ÓÃÜËã·¨
´æ´¢ÃÜÂëʹÓÃ×Ô½ç˵¼ÓÃÜËã·¨£¬£¬£¬¸ÃËã·¨½«ÃÜÂëÓëÓ²±àÂëÖµ*j7a(L#yZ98sSd5HfSgGjMj8;Ss;d)(*&^#@$a2s0i3g¾ÙÐÐÒì»ò£¬£¬£¬ÈçÏÂËùʾ£º
7. ÖÎÀí½çÃæ²»Çå¾²
ĬÈÏÇéÐÎÏ£¬£¬£¬Ö»ÄÜʹÓÃHTTP¡¢telnetºÍSNMPÔ¶³ÌÖÎÀí×°±¸£¬£¬£¬²»Ö§³ÖHTTPS»òSSH£¬£¬£¬¹¥»÷Õß¿ÉÒÔ×èµ²ÒÔÃ÷ÎÄÐÎʽ·¢Ë͵ÄÃÜÂ룬£¬£¬²¢Í¨¹ýÖÐÐÄÈ˹¥»÷£¨MITM£©À´Ð®ÖÆ×°±¸¡£¡£¡£¡£¡£¡£¡£
0x02 Ïà¹ØÐÂÎÅ
https://seclists.org/fulldisclosure/2020/Jul/7
0x03 ²Î¿¼Á´½Ó
https://pierrekim.github.io/advisories/2020-cdata-0x00-olt.txt
https://pierrekim.github.io/blog/2020-07-07-cdata-olt-0day-vulnerabilities.html
http://pierrekim.github.io/blog/2016-11-01-gpon-ftth-networks-insecurity.html
0x04 ʱ¼äÏß
2020-07-08 VSRCÐû²¼Îó²îͨ¸æ


¾©¹«Íø°²±¸11010802024551ºÅ