KEVIntel
7.5
CVSS
High

CVE-2022-24990

PUBLISHED

TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to...

Exploited in the wild Used in malware Remote Low complexity No user interaction
Vendor
TerraMaster
Product
NAS
Published
Feb 07, 2023
EPSS

Description

TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.

php cisa malware ransomware nuclei_scanner metasploit

CVSS scores

CVSS v3.1 7.5 High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Exploitation status

Exploited in the wild

Recorded 2023-02-10 00:00:00 UTC · Source

Used in malware

Recorded 2023-02-10 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Feb 10, 2023

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

jsongmax/terraMaster-CVE-2022-24990

github · Created 2022-10-17 07:54:13 UTC · 4 stars

ZZ-SOCMAP/CVE-2022-24990

github · Created 2022-04-12 02:45:56 UTC · 3 stars

TerraMaster TOS Unauthenticated Remote Command Execution(RCE) Vulnerability CVE-2022-24990

lishang520/CVE-2022-24990

github · Created 2022-03-20 05:21:08 UTC · 39 stars

CVE-2022-24990信息泄露+RCE 一条龙

0xf4n9x/CVE-2022-24990

github · Created 2022-03-20 05:15:16 UTC · 15 stars

CVE-2022-24990 TerraMaster TOS unauthenticated RCE via PHP Object Instantiation

VVeakee/CVE-2022-24990-POC

github · Created 2022-03-10 03:16:04 UTC · 4 stars

仅仅是poc,并不是exp

Jaky5155/CVE-2022-24990-TerraMaster-TOS--PHP-

github · Created 2022-03-08 01:28:32 UTC · 2 stars

CVE-2022-24990:TerraMaster TOS 通过 PHP 对象实例化执行未经身份验证的远程命令

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit