Lucene search

K
cve[email protected]CVE-2022-24989
HistoryAug 20, 2023 - 6:15 p.m.

CVE-2022-24989

2023-08-2018:15:09
CWE-74
web.nvd.nist.gov
34
In Wild
cve-2022-24989
terramaster
nas
remote execution
arbitrary code
security vulnerability
nvd

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.2 High

AI Score

Confidence

High

0.939 High

EPSS

Percentile

99.2%

TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI. (Shell metacharacters can be placed in raidtype because popen is used without any sanitization.) The credentials from CVE-2022-24990 exploitation can be used.

Affected configurations

NVD
Node
terra-masterterramaster_operating_systemRange<4.2.31
AND
terra-masterf2-210Match-
OR
terra-masterf2-221Match-
OR
terra-masterf2-223Match-
OR
terra-masterf2-422Match-
OR
terra-masterf2-423Match-
OR
terra-masterf4-421Match-
OR
terra-masterf4-422Match-
OR
terra-masterf4-423Match-
OR
terra-masterf5-221Match-
OR
terra-masterf5-422Match-
OR
terra-mastert12-423Match-
OR
terra-mastert12-450Match-
OR
terra-mastert6-423Match-
OR
terra-mastert9-423Match-
OR
terra-mastert9-450Match-
OR
terra-masteru12-322-9100Match-
OR
terra-masteru12-423Match-
OR
terra-masteru12-722-2224Match-
OR
terra-masteru16-322-9100Match-
OR
terra-masteru16-722-2224Match-
OR
terra-masteru24-722-2224Match-
OR
terra-masteru4-111Match-
OR
terra-masteru4-211Match-
OR
terra-masteru4-423Match-
OR
terra-masteru8-111Match-
OR
terra-masteru8-322-9100Match-
OR
terra-masteru8-423Match-
OR
terra-masteru8-522-9400Match-
OR
terra-masteru8-722-2224Match-

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.2 High

AI Score

Confidence

High

0.939 High

EPSS

Percentile

99.2%