Executive brief
Buffalo TeraStation TS5400R storage devices contain a security flaw where sensitive system files have incorrect access permissions. An authorized user with high-level privileges can exploit this to access the device's password file, potentially allowing them to retrieve hashed passwords for all accounts, including the administrator (root). This could lead to full system compromise if the passwords are successfully decrypted.
Technical details
An incorrect permission assignment (CWE-732) in Buffalo TeraStation NAS TS5400R firmware (v4.02-0.06 and prior) results in the /etc/shadow file being world-readable. An authenticated attacker with high privileges can exploit this by uploading and executing a PHP file via the webserver to read the file contents. This allows the attacker to retrieve hashed passwords for all configured system accounts, including root. The product has reportedly reached end-of-life (EOL) status, and no official patch is currently noted.
Affected products
- Buffalo TeraStation NAS TS5400R firmware 4.02-0.06 and prior
Timeline
- 2026-03-16: disclosed: Initial disclosure by VulnCheck
- 2026-03-16: advisory