目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2020-36109 PoC — ASUS RT-AX86U 安全漏洞

来源
关联漏洞
标题: ASUS RT-AX86U 安全漏洞 (CVE-2020-36109)
Description:ASUS RT-AX86U是中国华硕(ASUS)公司的一款无线路由器。 ASUS RT-AX86U router firmware 存在安全漏洞,该漏洞源于httpd模块的blocking request.cgi函数中出现缓冲区溢出,当攻击者构造恶意数据时,会导致代码执行。
Description
CVE-2020-36109  PoC causing DoS
介绍
# CVE-2020-36109-POC
> Feb 13 2021, Altin Thartori, github.com/tin-z

---

## Vulnerability details ##
ASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function of the httpd module that can cause code execution when an attacker constructs malicious data.

The vulnerability is not only present in RT-AX86U but also in other models using httpd service. [details](#more-details)

references:
 * [nist report](https://nvd.nist.gov/vuln/detail/CVE-2020-36109)
 * [cvebase](https://www.cvebase.com/cve/2020/36109)


## Exploit details ##

The vulnerability does not permit us to achieve RCE, in fact, only DoS was achieved.
In first place because of the canary, and secondly because 'strcat' does not copy NULL bytes and then we cannot overwrite canary nor craft ROP.
And also the buffer was placed just below the canary.

Prerequisites:
 - The target should have the same time zone, otherwise change the PoC
 - The value of 'Referer' header should contain the target's address
 - 'mac' parameter value must be equal to 'MULTIFILTER_MAC' nvram value 

<p align="center"><img src="./workmeme.jpg" width="50%" height="50%"></p>

### PoC ###
  * [poc.py](./poc.py)

![poc](poc.jpg)

### more details ###
```
Table 1. Versions of the vulnerable asus routers

| Model                   | Version           | date 
-------------------------------------------------------------------
| RT-AX86U                | 3.0.0.4.384.9318  | 2020/10/23
| ROG Rapture GT-AC5300   | 3.0.0.4.384.81974 | 2020/07/13 
| ROG Rapture GT-AX11000  | 3.0.0.4.384.9566  | 2020/08/06 

 ...                        ,,,                         ,,,

```


文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →