CVE-2022-24990
גבוהה 7.5 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- TerraMaster OS Remote Command Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 84% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-306
מוצרים מושפעים
terra-master: terramaster operating system; terra-master: f2-210; terra-master: f2-221; terra-master: f2-223; terra-master: f2-422; terra-master: f2-423; terra-master: f4-421; terra-master: f4-422; terra-master: f4-423; terra-master: f5-221; terra-master: f5-422; terra-master: t12-423; terra-master: t12-450; terra-master: t6-423; terra-master: t9-423
קישורים
- http://packetstormsecurity.com/files/172904/TerraMaster-TOS-4.2.29-Remote-Code… ExploitThird Party AdvisoryVDB Entry
- https://github.com/0xf4n9x/CVE-2022-24990 ExploitThird Party Advisory
- https://octagon.net/blog/2022/03/07/cve-2022-24990-terrmaster-tos-unauthentica… ExploitThird Party Advisory
- http://packetstormsecurity.com/files/172904/TerraMaster-TOS-4.2.29-Remote-Code… ExploitThird Party AdvisoryVDB Entry
- https://github.com/0xf4n9x/CVE-2022-24990 ExploitThird Party Advisory
- https://octagon.net/blog/2022/03/07/cve-2022-24990-terrmaster-tos-unauthentica… ExploitThird Party Advisory
- https://forum.terra-master.com/en/viewforum.php?f=28 Issue TrackingRelease Notes
- https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=… Third Party Advisory
- https://forum.terra-master.com/en/viewforum.php?f=28 Issue TrackingRelease Notes
- https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=… Third Party Advisory