CVE-2021-26620

HIGH

iptime NAS Firmware < 1.4.82 - Improper Authentication and Information Disclosure

Title source: llm
STIX 2.1

Description

An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentication when accessing the shared folder and changing user’s passwords.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0130
EPSS Percentile 66.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-287
Status published
Products (9)
iptime/nas-i_firmware < 1.4.82
iptime/nas-ii_firmware < 1.4.82
iptime/nas-iie_firmware < 1.4.82
iptime/nas101_firmware < 1.4.82
iptime/nas1dual_firmware < 1.4.82
iptime/nas2dual_firmware < 1.4.82
iptime/nas3_firmware < 1.4.82
iptime/nas4_firmware < 1.4.82
iptime/nas4dual_firmware < 1.4.82
Published Mar 25, 2022
Tracked Since Feb 18, 2026