CVE-2026-29516
EUVD-2026-1249416.03.2026, 20:16
Buffalo TeraStation NAS TS5400R firmware version 4.02-0.06 and prior contain an excessive file permissions vulnerability that allows authenticated attackers to read the /etc/shadow file by uploading and executing a PHP file through the webserver. Attackers can exploit world-readable permissions on /etc/shadow to retrieve hashed passwords for all configured accounts including root.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| buffaloamericas | terastation_nas_ts5400r_firmware | 𝑥 ≤ 4.02-0.06 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration