Vulnerability Description
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Terra-Master | Terramaster Operating System | < 4.2.31 |
| Terra-Master | F2-210 | - |
| Terra-Master | F2-221 | - |
| Terra-Master | F2-223 | - |
| Terra-Master | F2-422 | - |
| Terra-Master | F2-423 | - |
| Terra-Master | F4-421 | - |
| Terra-Master | F4-422 | - |
| Terra-Master | F4-423 | - |
| Terra-Master | F5-221 | - |
| Terra-Master | F5-422 | - |
| Terra-Master | T12-423 | - |
| Terra-Master | T12-450 | - |
| Terra-Master | T6-423 | - |
| Terra-Master | T9-423 | - |
| Terra-Master | T9-450 | - |
| Terra-Master | U12-322-9100 | - |
| Terra-Master | U12-423 | - |
| Terra-Master | U12-722-2224 | - |
| Terra-Master | U16-322-9100 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/172904/TerraMaster-TOS-4.2.29-Remote-Code-EExploitThird Party AdvisoryVDB Entry
- https://forum.terra-master.com/en/viewforum.php?f=28Issue TrackingRelease Notes
- https://github.com/0xf4n9x/CVE-2022-24990ExploitThird Party Advisory
- https://octagon.net/blog/2022/03/07/cve-2022-24990-terrmaster-tos-unauthenticateExploitThird Party Advisory
- https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=33Third Party Advisory
- http://packetstormsecurity.com/files/172904/TerraMaster-TOS-4.2.29-Remote-Code-EExploitThird Party AdvisoryVDB Entry
- https://forum.terra-master.com/en/viewforum.php?f=28Issue TrackingRelease Notes
- https://github.com/0xf4n9x/CVE-2022-24990ExploitThird Party Advisory
- https://octagon.net/blog/2022/03/07/cve-2022-24990-terrmaster-tos-unauthenticateExploitThird Party Advisory
- https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=33Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-US Government Resource
FAQ
What is CVE-2022-24990?
CVE-2022-24990 is a vulnerability with a CVSS score of 7.5 (HIGH). TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in th...
How severe is CVE-2022-24990?
CVE-2022-24990 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-24990?
Check the references section above for vendor advisories and patch information. Affected products include: Terra-Master Terramaster Operating System, Terra-Master F2-210, Terra-Master F2-221, Terra-Master F2-223, Terra-Master F2-422.