Vulnerabilities
Vulnerable Software
Terra-Master:  >> U12-423  Security Vulnerabilities
TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI. (Shell metacharacters can be placed in raidtype because popen is used without any sanitization.) The credentials from CVE-2022-24990 exploitation can be used.
CVSS Score
9.8
EPSS Score
0.776
Published
2023-08-20
CVE-2022-24990
Known exploited
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.
CVSS Score
7.5
EPSS Score
0.944
Published
2023-02-07


Contact Us

Shodan ® - All rights reserved