CVE-2022-24990
KEV ransomware PoC ×3largeUnauthenticated RCE via Admin Password Leak in TerraMaster TOS 4.2.29 and earlier
CISA: TerraMaster OS Remote Command Execution Vulnerability
TerraMaster TOS (TerraMaster OS) versions 4.2.29 and earlier do not require authentication (CWE-306) on the mobile API endpoint module/api.php?mobile/webNasIPS, and a request presenting the User-Agent "TNAS" returns system information that includes the administrative account's password in the PWD field. An unauthenticated attacker with network access to the NAS web interface can send this request and read the response, obtaining full administrative credentials. With those credentials an attacker controls the NAS, and public proof-of-concept exploits chain this flaw with a PHP object-instantiation bug to achieve unauthenticated remote command execution. Any TerraMaster NAS running TOS 4.2.29 or earlier is affected, with internet-exposed devices at the greatest risk. Exploitation is confirmed: the flaw is in CISA's Known Exploited Vulnerabilities Catalog (added 2023-02-10) with known ransomware use, carries an EPSS of roughly 84%, and CISA and press reports describe active attacks, including North Korean ransomware activity against healthcare and critical infrastructure.
What to do: Upgrade TerraMaster TOS to a release newer than 4.2.29 per the vendor's instructions, as required by the CISA KEV entry. If patching must wait, restrict the TOS web interface to trusted networks so unauthenticated users cannot reach module/api.php?mobile/webNasIPS. Check device logs for requests to the webNasIPS endpoint with a TNAS User-Agent and look for signs of post-compromise activity, since ransomware use of this flaw is known.
| TerraMaster OS (TOS) on TerraMaster NAS devices | 4.2.29 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.
- Affected
- TerraMaster TerraMaster OS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- terra-master
- Products
- terramaster operating system
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N