CVE-2026-91191 设备更新机制签名验证绕过漏洞
影响攻击者可安装恶意软件包并以 root 权限执行任意代码
该漏洞存在于设备的固件更新机制中。启动过程中,stock done 函数会在从可写且未签名的 feed 恢复可选包之前禁用 OPKG 配置中的签名验证。此外,公开分发的 SDK 中包含了生产私钥,其对应公钥被稳定版和测试版固件信任。两个问题都会破坏软件包的真实性,结合利用可使攻击者提供的包被系统视为合法。
影响范围
受影响的具体产品与版本范围暂无公开信息,涉及使用该更新机制及 OPKG 包管理的设备固件。
漏洞详情
漏洞类型为签名验证绕过。成因一是启动流程中 stock done 函数在恢复可选包前关闭了 OPKG 的签名校验,二是公开 SDK 泄露了生产私钥,而该私钥对应的公钥被固件信任。攻击者可借此构造看似合法的恶意软件包,在安装时以 root 权限执行任意代码。
利用条件与风险
利用前提是攻击者能够向设备提供恶意软件包,例如通过可写 feed 或中间人方式。实战中可导致设备被完全控制,风险较高。
修复建议
官方修复方案与临时缓解措施暂无公开信息,建议关注厂商公告并及时更新固件,同时限制对更新源和软件包分发渠道的访问。
The device’s update mechanism includes conditions that allow unauthorized software packages to be accepted as authentic. During the boot process, the stock done function disables signature verification in the OPKG configuration before restoring optional packages from a writable, unsigned feed. Separately, the publicly distributed SDK contains the production private key whose corresponding public key is trusted by both stable and beta firmware builds. Either issue undermines package authenticity, and together they allow an attacker to provide packages that appear valid to the system. Even if signature enforcement is restored, the exposed production key enables an attacker to generate signatures that the device will continue to trust. An attacker who can supply a malicious package may be able to execute arbitrary code with root privileges during installation.