First published: Mon Apr 25 2022(Updated: )
It is possible to obtain the first administrator's hash set up on the system in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) as well as other information such as MAC address, internal IP address etc. by performing a request to the /module/api.php?mobile/webNasIPS endpoint.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TerraMaster TOS | =4.2.15-2107141517 | |
Terra-master F2-210 | ||
Terra-master F4-210 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45839 is considered a critical vulnerability due to the possibility of exposing sensitive administrator credentials.
To fix CVE-2021-45839, update the TerraMaster TOS to the latest version that addresses this vulnerability.
CVE-2021-45839 affects the TerraMaster TOS 4.2.15-2107141517 and the associated F4-210 and F2-210 NAS devices.
Through CVE-2021-45839, an attacker can obtain the first administrator's hash, MAC address, and internal IP address.
CVE-2021-45839 can lead to unauthorized access and exploitation of the affected NAS systems due to credential exposure.