Description
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.
Published: 2023-02-07
Score: 9.8 Critical
EPSS: 94.4% High
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Oct 2025 23:15:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Mon, 03 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

kev

{'dateAdded': '2023-02-10'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Terra-master F2-210 F2-221 F2-223 F2-422 F2-423 F4-421 F4-422 F4-423 F5-221 F5-422 T12-423 T12-450 T6-423 T9-423 T9-450 Terramaster Operating System U12-322-9100 U12-423 U12-722-2224 U16-322-9100 U16-722-2224 U24-722-2224 U4-111 U4-211 U4-423 U8-111 U8-322-9100 U8-423 U8-522-9400 U8-722-2224
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-10-21T23:15:27.378Z

Reserved: 2022-02-14T00:00:00.000Z

Link: CVE-2022-24990

cve-icon Vulnrichment

Updated: 2024-08-03T04:29:01.557Z

cve-icon NVD

Status : Analyzed

Published: 2023-02-07T18:15:09.100

Modified: 2025-11-07T19:02:38.613

Link: CVE-2022-24990

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses