CVE-2022-24990
HIGH KEV RANSOMWARE NUCLEITerraMaster TOS 4.2.29 or lower - Unauthenticated RCE chaining CVE-2022-24990 and CVE-2022-24989
Title source: metasploitDescription
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.
Exploits (7)
nomisec
WORKING POC
4 stars
by jsongmax · remote
https://github.com/jsongmax/terraMaster-CVE-2022-24990
nomisec
WORKING POC
2 stars
by Jaky5155 · poc
https://github.com/Jaky5155/CVE-2022-24990-TerraMaster-TOS--PHP-
metasploit
WORKING POC
EXCELLENT
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/terramaster_unauth_rce_cve_2022_24990.rb
Nuclei Templates (1)
TerraMaster TOS < 4.2.30 Server Information Disclosure
HIGHby dwisiswant0
Shodan:
TerraMaster || terramaster
References (6)
Scores
CVSS v3
7.5
EPSS
0.9440
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CISA KEV
2023-02-10
VulnCheck KEV
2022-04-11
InTheWild.io
2023-02-10
ENISA EUVD
EUVD-2022-29737
Ransomware Use
Confirmed
CWE
CWE-306
Status
published
Products (1)
terra-master/terramaster_operating_system
< 4.2.31
Published
Feb 07, 2023
KEV Added
Feb 10, 2023
Tracked Since
Feb 18, 2026