CVE-2024-34539

CRITICAL

TerraMaster TOS <5.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Hardcoded credentials in TerraMaster TOS firmware through 5.1 allow a remote attacker to successfully login to the mail or webmail server. These credentials can also be used to login to the administration panel and to perform privileged actions.

Scores

CVSS v3 9.4
EPSS 0.0052
EPSS Percentile 67.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-259
Status published
Published Jun 14, 2024
Tracked Since Feb 18, 2026