目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-107785— Crux Agent SHA-512对等协商时SKA预共享密钥轮换静默失败

一分钟漏洞结论

影响对象
Sirius Computer, Inc. Crux Agent
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

漏洞描述: Crux Agent 1.9.0 至 2.0.3(不含 2.0.3)版本在使用全长的 SKA bilocation 密钥作为 WireGuard 预共享密钥(preshared key)时存在安全问题。当对等会话协商使用 SHA-512 算法时,生成的密钥长度为 64 字节,而 WireGuard 要求预共享密钥长度必须为 32 字节。该代理未对此密钥长度进行有效性验证,而是尝试通过执行 命令来更新活动隧道配置,并将无效的密钥写入 WireGuard 配置文件。由于密钥长度不合法,配置更新失败,导致活动

CVSS 6.3 · Medium

可能的 ATT&CK 技术 1 AI

T1557.002 · ARP Cache Poisoning
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-107785 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Crux Agent silently fails SKA preshared key rotation when SHA-512 peering is negotiated
来源: CVE Program / CVE List V5
Vulnerability Description
Crux Agent from 1.9.0 before 2.0.3 uses the full SKA bilocation key as the WireGuard preshared key. When a peering session negotiates use of SHA-512, the key produced is 64 bytes instead of the 32 bytes WireGuard requires. The agent does not validate this size; instead it attempts to use the `wg set` command to update the live tunnel, and write the invalid key to the WireGuard configuration file. The update fails, so the live tunnel keeps using its previous preshared key until the tunnel is shut down. The tunnel will fail to start when restarted. For a peer which has never successfully negotiated a 32-byte bilocation key in a Crux C2 organization which has the "Enforce SKA Use" setting turned off, no preshared key will be set for the tunnel. Therefore, an attacker who is able to intercept and store the peer's traffic, and has access (or will have access) to a cryptographically relevant quantum computer, will be able to decrypt the tunnel.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U/S:N/AU:Y/R:A/V:C/RE:L/U:Amber
来源: CVE Program / CVE List V5
Vulnerability Type
未预期的状态编码或返回值
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Sirius Computer, Inc. Crux Agent 1.9.0 ~ 2.0.3 -

二、漏洞 CVE-2026-107785 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-107785 的情报信息

请登录查看更多情报信息。

CVE-2026-107785 其他参考 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-107785

暂无评论


发表评论