CVE-2022-24990
07.02.2023, 18:15
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.Enginsight
Vendor | Product | Version |
---|---|---|
terra-master | terramaster_operating_system | 𝑥 < 4.2.31 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References