First published: Tue Feb 07 2023(Updated: )
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Terra-master Terramaster Operating System | <4.2.31 | |
Terra-master F2-210 | ||
Terra-master F2-221 | ||
Terra-master F2-223 | ||
Terra-master F2-422 | ||
Terra-master F2-423 | ||
Terra-master F4-421 | ||
Terra-master F4-422 | ||
Terra-master F4-423 | ||
Terra-master F5-221 | ||
Terra-master F5-422 | ||
Terra-master T12-423 | ||
Terra-master T12-450 | ||
Terra-master T6-423 | ||
Terra-master T9-423 | ||
Terra-master T9-450 | ||
Terra-master U12-322-9100 | ||
Terra-master U12-423 | ||
Terra-master U12-722-2224 | ||
Terra-master U16-322-9100 | ||
Terra-master U16-722-2224 | ||
Terra-master U24-722-2224 | ||
Terra-master U4-111 | ||
Terra-master U4-211 | ||
Terra-master U4-423 | ||
Terra-master U8-111 | ||
Terra-master U8-322-9100 | ||
Terra-master U8-423 | ||
Terra-master U8-522-9400 | ||
Terra-master U8-722-2224 | ||
All of | ||
Terra-master Terramaster Operating System | <4.2.31 | |
Any of | ||
Terra-master F2-210 | ||
Terra-master F2-221 | ||
Terra-master F2-223 | ||
Terra-master F2-422 | ||
Terra-master F2-423 | ||
Terra-master F4-421 | ||
Terra-master F4-422 | ||
Terra-master F4-423 | ||
Terra-master F5-221 | ||
Terra-master F5-422 | ||
Terra-master T12-423 | ||
Terra-master T12-450 | ||
Terra-master T6-423 | ||
Terra-master T9-423 | ||
Terra-master T9-450 | ||
Terra-master U12-322-9100 | ||
Terra-master U12-423 | ||
Terra-master U12-722-2224 | ||
Terra-master U16-322-9100 | ||
Terra-master U16-722-2224 | ||
Terra-master U24-722-2224 | ||
Terra-master U4-111 | ||
Terra-master U4-211 | ||
Terra-master U4-423 | ||
Terra-master U8-111 | ||
Terra-master U8-322-9100 | ||
Terra-master U8-423 | ||
Terra-master U8-522-9400 | ||
Terra-master U8-722-2224 | ||
TerraMaster TOS | ||
All of | ||
<4.2.31 | ||
Any of | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24990 is classified as a critical severity vulnerability due to its potential for remote code execution and unauthorized access.
To fix CVE-2022-24990, upgrade TerraMaster OS to version 4.2.31 or later to patch the vulnerability.
CVE-2022-24990 allows remote attackers to discover and exploit administrative passwords, potentially leading to full system compromise.
Versions of TerraMaster OS prior to 4.2.31, specifically 4.2.29 and earlier, are affected by CVE-2022-24990.
Yes, CVE-2022-24990 can be exploited remotely by sending crafted requests to vulnerable TerraMaster NAS devices.