First published: Mon Apr 25 2022(Updated: )
It is possible to obtain the first administrator's hash set up in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) on the system as well as other information such as MAC address, internal IP address etc. by performing a request to the /module/api.php?mobile/wapNasIPS endpoint.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TerraMaster TOS | =4.2.15-2107141517 | |
Terra-master F2-210 | ||
Terra-master F4-210 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45842 is considered a high-severity vulnerability due to the potential exposure of sensitive administrator information.
To mitigate CVE-2021-45842, it is recommended to update TerraMaster TOS to a version that addresses this vulnerability.
Exploiting CVE-2021-45842 allows attackers to access the first administrator's hash, MAC address, and internal IP address.
CVE-2021-45842 specifically affects TerraMaster TOS version 4.2.15-2107141517.
The TerraMaster F2-210 and F4-210 are not directly affected by CVE-2021-45842, as the vulnerability pertains to TOS version 4.2.15-2107141517.