CVE-2022-24990
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply updates per vendor instructions.
TerraMaster NAS devices running version 4.2.29 or earlier leak the administrator password in plain text when a specially crafted web request is made. An attacker can easily retrieve the admin password remotely without needing any credentials.
The vulnerability exists in module/api.php endpoint (mobile/webNasIPS function) which fails to implement access controls (CWE-306) and returns the PWD field containing plaintext administrative credentials when requests include the 'TNAS' User-Agent header. Remote unauthenticated attackers can enumerate admin credentials, leading to full NAS compromise.
The full analysis of this CVE is available in Portuguese →