Executive brief
TerraMaster TOS (TerraMaster Operating System) contains a vulnerability that allows unauthenticated remote attackers to discover administrative passwords by sending a specific User-Agent header to a mobile API endpoint. This information disclosure can be leveraged to achieve remote command execution on the affected NAS device.
Affected products
- TerraMaster TOS (TerraMaster Operating System) <= 4.2.29
- TerraMaster NAS Hardware (F2-210, F2-221, F2-223, F2-422, F2-423, F4-421, F4-422, F4-423, F5-221, F5-422, T12-423, T12-450, T6-423, T9-423, T9-450, U12-322-9100, U12-423, U12-722-2224, U16-322-9100, U16-722-2224, U24-722-2224, U4-111, U4-211, U4-423, U8-111, U8-322-9100)
Timeline
- 2022-03-07: disclosed: Initial public disclosure of the vulnerability details.
- 2023-02-10: kev added: Added to CISA's Known Exploited Vulnerabilities (KEV) Catalog.
- 2023-02-10: advisory: NVD publication date.