Junglewise Threat Intelligence

CVE-2026-29516: Buffalo TeraStation NAS TS5400R excessive file permissions in /etc/shadow

CVE-2026-29516 · Severity: medium · CVSS 4.9 · Published 2026-03-16

Executive brief

Buffalo TeraStation TS5400R storage devices contain a security flaw where sensitive system files have incorrect access permissions. An authorized user with high-level privileges can exploit this to access the device's password file, potentially allowing them to retrieve hashed passwords for all accounts, including the administrator (root). This could lead to full system compromise if the passwords are successfully decrypted.

Technical details

An incorrect permission assignment (CWE-732) in Buffalo TeraStation NAS TS5400R firmware (v4.02-0.06 and prior) results in the /etc/shadow file being world-readable. An authenticated attacker with high privileges can exploit this by uploading and executing a PHP file via the webserver to read the file contents. This allows the attacker to retrieve hashed passwords for all configured system accounts, including root. The product has reportedly reached end-of-life (EOL) status, and no official patch is currently noted.

Affected products

  • Buffalo TeraStation NAS TS5400R firmware 4.02-0.06 and prior

Timeline

  • 2026-03-16: disclosed: Initial disclosure by VulnCheck
  • 2026-03-16: advisory

References