CVE-2022-24990
KEV RANSOMWARECRITICAL 9.8EPSS 83.6%
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 83.55% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2023-02-10, used in ransomware campaigns
- Nuclei
- high · CWE-306
- Published
- 2023-02-07
- Updated
- 2025-10-21
Proof-of-concept exploits (8)
- http://packetstormsecurity.com/files/172904/TerraMaster-TOS-4.2.29-Remote-Code-Execution.…
- 0xf4n9x/CVE-2022-2499012★ · 2022-04-25
- Jaky5155/CVE-2022-24990-TerraMaster-TOS--PHP-2★ · 2022-03-08
- VVeakee/CVE-2022-24990-POC4★ · 2022-03-15
- ZZ-SOCMAP/CVE-2022-249903★ · 2022-04-12
- antx-code/CVE-2022-249903★ · 2022-04-12
- jsongmax/terraMaster-CVE-2022-249904★ · 2022-10-17
- lishang520/CVE-2022-2499038★ · 2022-03-29