ZeroHour

CVE-2022-24990

KEV ransomware PoC ×3large

Unauthenticated RCE via Admin Password Leak in TerraMaster TOS 4.2.29 and earlier

CISA: TerraMaster OS Remote Command Execution Vulnerability

CVSS 3.1
7.5 high
EPSS
84%p100
Published
()
KEV added
AI analysis

TerraMaster TOS (TerraMaster OS) versions 4.2.29 and earlier do not require authentication (CWE-306) on the mobile API endpoint module/api.php?mobile/webNasIPS, and a request presenting the User-Agent "TNAS" returns system information that includes the administrative account's password in the PWD field. An unauthenticated attacker with network access to the NAS web interface can send this request and read the response, obtaining full administrative credentials. With those credentials an attacker controls the NAS, and public proof-of-concept exploits chain this flaw with a PHP object-instantiation bug to achieve unauthenticated remote command execution. Any TerraMaster NAS running TOS 4.2.29 or earlier is affected, with internet-exposed devices at the greatest risk. Exploitation is confirmed: the flaw is in CISA's Known Exploited Vulnerabilities Catalog (added 2023-02-10) with known ransomware use, carries an EPSS of roughly 84%, and CISA and press reports describe active attacks, including North Korean ransomware activity against healthcare and critical infrastructure.

What to do: Upgrade TerraMaster TOS to a release newer than 4.2.29 per the vendor's instructions, as required by the CISA KEV entry. If patching must wait, restrict the TOS web interface to trusted networks so unauthenticated users cannot reach module/api.php?mobile/webNasIPS. Check device logs for requests to the webNasIPS endpoint with a TNAS User-Agent and look for signs of post-compromise activity, since ransomware use of this flaw is known.

Affected
TerraMaster OS (TOS) on TerraMaster NAS devices4.2.29 and earlier
Estimated exposure
largeon the order of tens of thousands of internet-exposed TerraMaster NAS devices (estimate, not a verified count) — TerraMaster is a small NAS vendor whose devices typically run a directly internet-exposed TOS web panel, so public scan coverage and the vendor's modest global install base support an exposed-device count in the tens of thousands, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.

CISA Known Exploited Vulnerability
Affected
TerraMaster TerraMaster OS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
terra-master
Products
terramaster operating system
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news