天下漏洞,尽知其名
HIGH

CVE-2026-84409 设备更新机制存储型 XSS 漏洞

影响攻击者可注入脚本并以 root 权限执行任意代码

AI 研判

该漏洞存在于设备的软件更新机制中。设备通过未加密的 HTTP 连接获取更新元数据并存储部分内容,管理接口随后在 JSON 响应中返回该值,而展示更新信息的 Web 界面将其直接作为 HTML 插入页面,导致存储型 XSS。由于同一已认证源提供可执行 root 权限系统命令的接口,攻击者可借此在设备管理上下文中执行任意代码。

影响范围

暂无公开信息

受影响的具体产品与版本范围暂无公开信息,涉及使用 HTTP 明文获取更新元数据并存在上述管理界面的设备固件。

漏洞详情

漏洞类型为存储型跨站脚本(XSS)并可能升级为远程代码执行。成因是更新元数据经 HTTP 明文传输且未做输入校验与输出编码,被直接以 HTML 形式插入页面。攻击者若能影响更新元数据,即可注入恶意脚本,并利用同源下具备 root 权限的命令执行接口实现任意代码执行。

利用条件与风险

利用前提是攻击者能够影响或篡改更新元数据(如中间人攻击或控制更新源),且目标管理界面可被访问。实战中可导致设备被完全控制,风险较高。

修复建议

官方修复方案暂无公开信息。建议临时缓解措施:将更新元数据获取改为 HTTPS 并校验来源,对存储与展示的元数据实施严格输入校验和输出编码,同时限制命令执行接口的访问权限。

原始情报

The device’s update mechanism retrieves metadata for software updates over an unencrypted HTTP connection and stores portions of that metadata for later use. A management interface subsequently returns this stored value in a JSON response, and the web interface responsible for displaying update information inserts that value directly into the page as HTML. This behavior allows attacker‑controlled metadata to be interpreted as script content. In addition, the same authenticated origin provides an interface capable of executing system‑level commands with root privileges. An attacker able to influence update metadata could exploit these conditions to execute arbitrary code within the administrative context of the device.