Urządzenia Zyxel NAS z firmware w wersji 5.21 zawierają krytyczną podatność typu command injection, która nie wymaga uwierzytelnienia. Zdalny atakujący może wykonać dowolny kod z uprawnieniami root bez posiadania jakichkolwiek danych uwierzytelniających.
▸ Pokaż oryginał (EN)
Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. ZyXEL NAS devices achieve authentication by using the weblogin.cgi CGI executable. This program fails to properly sanitize the username parameter that is passed to it. If the username parameter contains certain characters, it can allow command injection with the privileges of the web server that runs on the ZyXEL device. Although the web server does not run as the root user, ZyXEL devices include a setuid utility that can be leveraged to run any command with root privileges. As such, it should be assumed that exploitation of this vulnerability can lead to remote code execution with root privileges. By sending a specially-crafted HTTP POST or GET request to a vulnerable ZyXEL device, a remote, unauthenticated attacker may be able to execute arbitrary code on the device. This may happen by directly connecting to a device if it is directly exposed to an attacker. However, there are ways to trigger such crafted requests even if an attacker does not have direct connectivity to a vulnerable devices. For example, simply visiting a website can result in the compromise of any ZyXEL device that is reachable from the client system. Affected products include: NAS326 before firmware V5.21(AAZF.7)C0 NAS520 before firmware V5.21(AASZ.3)C0 NAS540 before firmware V5.21(AATB.4)C0 NAS542 before firmware V5.21(ABAG.4)C0 ZyXEL has made firmware updates available for NAS326, NAS520, NAS540, and NAS542 devices. Affected models that are end-of-support: NSA210, NSA220, NSA220+, NSA221, NSA310, NSA310S, NSA320, NSA320S, NSA325 and NSA325v2
Podatność tkwi w skrypcie CGI weblogin.cgi, odpowiedzialnym za obsługę logowania do interfejsu webowego urządzenia. Parametr username przekazywany do tego skryptu nie jest odpowiednio sanitizowany, co umożliwia wstrzyknięcie poleceń systemowych (command injection) poprzez specjalnie spreparowane żądanie HTTP POST lub GET. Mimo że serwer WWW na urządzeniu nie działa na koncie root, Zyxel dostarcza narzędzie z ustawionym bitem setuid, które może zostać wykorzystane do eskalacji uprawnień i uruchomienia dowolnych poleceń z uprawnieniami root. Co istotne, atak może być wyzwolony pośrednio — samo odwiedzenie przez ofiarę złośliwej strony internetowej może spowodować przejęcie urządzenia NAS dostępnego z sieci klienta.
Atakujący może zdalnie wykonać dowolny kod z uprawnieniami root na podatnym urządzeniu bez jakiegokolwiek uwierzytelnienia, co prowadzi do pełnego przejęcia kontroli nad urządzeniem, utraty poufności danych oraz możliwości dalszego ataku na sieć wewnętrzną.
Należy natychmiast zaktualizować firmware: NAS326 do V5.21(AAZF.7)C0 lub nowszego, NAS520 do V5.21(AASZ.3)C0 lub nowszego, NAS540 do V5.21(AATB.4)C0 lub nowszego, NAS542 do V5.21(ABAG.4)C0 lub nowszego. Urządzenia z serii NSA (NSA210, NSA220, NSA220+, NSA221, NSA310, NSA310S, NSA320, NSA320S, NSA325, NSA325v2) są wycofane z wsparcia i nie otrzymają patchy — należy rozważyć ich natychmiastowe wyłączenie lub odizolowanie od sieci. Krytycznie ważne jest, aby żadne podatne urządzenie NAS nie było bezpośrednio dostępne z Internetu.
Zyxel NAS326 przed firmware V5.21(AAZF.7)C0, NAS520 przed firmware V5.21(AASZ.3)C0, NAS540 przed firmware V5.21(AATB.4)C0, NAS542 przed firmware V5.21(ABAG.4)C0. Urządzenia wycofane z wsparcia (end-of-support) bez dostępnych patchy: NSA210, NSA220, NSA220+, NSA221, NSA310, NSA310S, NSA320, NSA320S, NSA325, NSA325v2.
Podatność jest szczególnie niebezpieczna ze względu na wektor ataku drive-by: użytkownik odwiedzający złośliwą stronę WWW może nieświadomie spowodować przejęcie urządzenia NAS dostępnego z jego sieci lokalnej, nawet jeśli urządzenie nie jest bezpośrednio wystawione na Internet. Urządzenia z serii NSA są wycofane z wsparcia i nie otrzymają aktualizacji firmware.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HZyxel Atp100
HWZyxelwszystkie wersjeZyxel Atp100 Firmware
OSZyxel4.35 – 4.35\(abps.3\)c0 (bez)Zyxel Atp200
HWZyxelwszystkie wersjeZyxel Atp200 Firmware
OSZyxel4.35 – 4.35\(abfw.3\)c0 (bez)Zyxel Atp500
HWZyxelwszystkie wersjeZyxel Atp500 Firmware
OSZyxel4.35 – 4.35\(abfu.3\)c0 (bez)Zyxel Atp800
HWZyxelwszystkie wersjeZyxel Atp800 Firmware
OSZyxel4.35 – 4.35\(abiq.3\)c0 (bez)Zyxel Nas326
HWZyxelwszystkie wersjeZyxel Nas326 Firmware
OSZyxel< 5.21\(aazf.7\)c0Zyxel Nas520
HWZyxelwszystkie wersjeZyxel Nas520 Firmware
OSZyxel< 5.21\(aasz.3\)c0Zyxel Nas540
HWZyxelwszystkie wersjeZyxel Nas540 Firmware
OSZyxel< 5.21\(aatb.4\)c0Zyxel Nas542
HWZyxelwszystkie wersjeZyxel Nas542 Firmware
OSZyxel< 5.21\(abag.4\)c0Zyxel Usg110
HWZyxelwszystkie wersjeZyxel Usg1100
HWZyxelwszystkie wersjeZyxel Usg1100 Firmware
OSZyxel4.35 – 4.35\(aapk.3\)c0 (bez)Zyxel Usg110 Firmware
OSZyxel4.35 – 4.35\(aaph.3\)c0 (bez)Zyxel Usg1900
HWZyxelwszystkie wersjeZyxel Usg1900 Firmware
OSZyxel4.35 – 4.35\(aapl.3\)c0 (bez)Zyxel Usg20 Vpn
HWZyxelwszystkie wersjeZyxel Usg20 Vpn Firmware
OSZyxel4.35 – 4.35\(abaq.3\)c0 (bez)Zyxel Usg20w Vpn
HWZyxelwszystkie wersjeZyxel Usg20w Vpn Firmware
OSZyxel4.35 – 4.35\(abar.3\)c0 (bez)Zyxel Usg210
HWZyxelwszystkie wersjeZyxel Usg210 Firmware
OSZyxel4.35 – 4.35\(aapi.3\)c0 (bez)Zyxel Usg2200
HWZyxelwszystkie wersjeZyxel Usg2200 Firmware
OSZyxel4.35 – 4.35\(abae.3\)c0 (bez)
CISA KEV — szczegółyi
- Dostawcai
- Zyxel
- Produkti
- Multiple Network-Attached Storage (NAS) Devices
- Data dodania do KEVi
- 25 marca 2022
- Termin remediation (USA)i
- 15 kwietnia 2022(po terminie)
Zastosuj aktualizacje zgodnie z instrukcjami producenta.
▸ Pokaż oryginał (EN)
Apply updates per vendor instructions.
Wiele urządzeń Zyxel network-attached storage (NAS) zawiera lukę command injection wymagającą uwierzytelnienia, która może pozwolić zdalnemu, nieuwierzytelnionemu atakującemu na wykonanie dowolnego kodu.
▸ Pokaż oryginał (EN)
Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code.
Powiązane podatności
Zyxel NAS — pre-authentication command injection w firmware NAS326/540/542
Buffer overflow w firmware Zyxel — RCE bez uwierzytelnienia (firewalle/VPN)
Buffer overflow w firmware Zyxel — RCE bez uwierzytelnienia
Zyxel Firewall/VPN — zdalny command injection bez uwierzytelnienia (RCE)
Command injection w firmware Zyxel USG FLEX i VPN — zdalne wykonanie poleceń OS