¡¾·ì϶¹«¸æ¡¿Realtek SDK 8Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-08-170x00 ·ì϶¸ÅÊö
2021Äê8ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±¹«¿ªÅû¶ÁĘ̈ÍåоƬÉè¼ÆÉÌRealtek¹«Ë¾µÄ SDKÖеÄ4¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÄÜÀûÓÃÕâЩ·ì϶ʹÉ豸±ÀÀ££¨»Ø¾ø·þÎñ£©¡¢×¢ÈëËÁÒâºÅÁî²¢ÒÔ×î¸ßȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶ÖÁÉÙÓ°ÏìÁË65¸ö·ÖÆç¹©¸øÉ̳ö²úµÄ½ü 200 ÖÖ²úÆ·£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ×÷Ϊ¹©¸øÁ´·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ËüÃÇÓ°ÏìÁ˹©¸øÁ´ÏÂÓεÄÊýÊ®Íǫ̀É豸¡£¡£¡£¡£¡£¡£¡£
0x01 ·ì϶ÏêÇé

ÔÚÎïÁªÍøÁìÓòµÄºÜ¶àǶÈëʽÉ豸Öж¼Äܹ»ÕÒµ½ Realtek оƬ×é¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬³¬¹ý 65 ¼ÒÓ²¼þÔì×÷É̵IJúƷѡȡÁË Realtek RTL819xD Ä£¿£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÄ£¿£¿£¿£¿£¿£¿£¿£¿éʵÏÖÁËÎÞÏß½ÓÈëµãÖ°Äܲ¢Ô̺¬ÆäÖÐÒ»¸öÒ×Êܹ¥»÷µÄ SDK¡£¡£¡£¡£¡£¡£¡£²¢ÇÒÊÜÓ°ÏìµÄÉ豸ʹÓÃ¿í·º£¬£¬£¬£¬£¬£¬£¬£¬´Ó×¡Õ¬Íø¹Ø¡¢¹Û¹â·ÓÉÆ÷¡¢Wi-Fi ÖÐ¼ÌÆ÷¡¢IP ÉãÏñ»úµ½ÖÇÄÜÉÁµçÍø¹Ø£¬£¬£¬£¬£¬£¬£¬£¬ÉõÖÁÊÇÁªÍøÍæ¾ß¡£¡£¡£¡£¡£¡£¡£
×êÑÐÈËÔ±Åû¶µÄ4¸ö·ì϶ÈçÏ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐǰ2¸ö·ì϶µÄCVSSÆÀ·ÖΪ8.1£¨¸ßΣ£©£¬£¬£¬£¬£¬£¬£¬£¬ºó2¸ö·ì϶µÄCVSSÆÀ·ÖΪ9.8£¨ÑϳÁ£©¡£¡£¡£¡£¡£¡£¡£µ«ÒªÀûÓÃÕâЩ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÐèÓëÉ豸ÔÚÍ³Ò»ÍøÂ磬£¬£¬£¬£¬£¬£¬£¬»òÕß¿ÉÄÜͨ¹ý»¥ÁªÍø½Ó¼ûÉ豸¡£¡£¡£¡£¡£¡£¡£
l CVE-2021-35392£ºÍ¨¹ý UPnP µÄ Wi-Fi µ¥Ò»ÅäÖòֿ⻺³åÇøÒç³ö
l CVE-2021-35393£ºÍ¨¹ý SSDP µÄ Wi-Fi µ¥Ò»ÅäÖöѻº³åÇøÒç³ö
l CVE-2021-35394£ºMP Daemon Õï¶Ï¹¤¾ßºÅÁî×¢Èë
l CVE-2021-35395£ºÖÎÀíWeb½çÃæ¶à¸ö·ì϶
Ó°ÏìÁìÓò
Realtek SDK v2.x
Realtek ¡°Jungle¡± SDK v3.0/v3.1/v3.2/v3.4.x/v3.4T/v3.4T-CT
Realtek ¡°Luna¡± SDK ×î¸ß°æ±¾ 1.3.2
0x02 ´ëÖý¨Òé
ĿǰÕâЩ·ì϶ÒѾÔÚ²¿ÃŰ汾Öн¨¸´¡£¡£¡£¡£¡£¡£¡£½¨Òé²Î¿¼ÒÔϰ汾ʵʱÉý¼¶¸üÐÂ:
Realtek SDK branch 2.x£ºRealtek²»ÔÙÖ§³Ö¡£¡£¡£¡£¡£¡£¡£
Realtek "Jungle" SDK£ºRealtekÔÚ¿ª·¢²¹¶¡£¬£¬£¬£¬£¬£¬£¬£¬ÐèÏòºóÒÆÖ²
Realtek "Luna" SDK£ºÉý¼¶µ½1.3.2a
ÏÂÔØÁ´½Ó£º
https://www.realtek.com/en/cu-1-en/cu-1-taiwan-en
ÒÑÖªµÄÊÜÓ°ÏìÔì×÷É̼°²úÆ·Á´½ÓÈçÏ£º£¨Éæ¼°D-Link¡¢»ªÎª¡¢ÁªÍ¨¡¢ºÏÇڵȣ©
https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain/
0x03 ²Î¿¼Á´½Ó
https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain/
https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf
https://www.theregister.com/2021/08/16/realtek_wifi_sdk_vulnerabilities/
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2021-08-17 | ³õ´Î°ä²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ8827Ì«Ñô¼¯ÍÅ
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬£¬£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ