HIGH

CVE-2022-24990

Terra-master Terramaster Operating System 2023-02-07 CVSS v3.1
CVSS
7.5
KEV

Description

TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.

Summary dbcve.org

TerraMaster NAS versions 4.2.29 and earlier contain an information disclosure vulnerability in the mobile API endpoint. Unauthenticated remote attackers can obtain the administrator password in plaintext by sending a specially crafted HTTP request with the User-Agent header set to 'TNAS' to module/api.php?mobile/webNasIPS, which returns the password in the PWD field of the response.

Mitigation

Apply the vendor patch if available. As an interim control, restrict network access to the NAS management interface using firewall rules or network segmentation to prevent untrusted remote attackers from reaching the vulnerable API endpoint.

Proof of Concept

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

83.55%
Probability of exploitation in next 30 days
99.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE