CVE-2022-24990criticalunder attackransomwareCWE-306

CVE-2022-24990

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 83%
from disclosure to weapon0 days
Published on NVDFeb 7
1st PoCMar 8
metasploitMar 7
CISA KEV+3d
exploitation probability
83%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
10 public exploit(s)
Action required by CISAfederal deadline: 2023-03-03

Apply updates per vendor instructions.

In short

TerraMaster NAS devices running version 4.2.29 or earlier leak the administrator password in plain text when a specially crafted web request is made. An attacker can easily retrieve the admin password remotely without needing any credentials.

Technical detail

The vulnerability exists in module/api.php endpoint (mobile/webNasIPS function) which fails to implement access controls (CWE-306) and returns the PWD field containing plaintext administrative credentials when requests include the 'TNAS' User-Agent header. Remote unauthenticated attackers can enumerate admin credentials, leading to full NAS compromise.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.