CVE-2022-24989
TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 31.9%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI. (Shell metacharacters can be placed in raidtype because popen is used without any sanitization.) The credentials from CVE-2022-24990 exploitation can be used.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 31.88% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- terra-master/terramaster operating system
- Source
- cve@mitre.org
References
- https://attackerkb.com/topics/h8YKVKx21t/cve-2022-24990Third Party Advisory
- https://forum.terra-master.com/en/viewforum.php?f=28Release Notes
- https://github.com/0xf4n9x/CVE-2022-24990Exploit
- https://octagon.net/blog/2022/03/07/cve-2022-24990-terrmaster-tos-unauthenticated-remote-command-execution-via-php-object-instantiationExploit
- https://packetstormsecurity.com/files/172904Exploit, Third Party Advisory, VDB Entry
- https://attackerkb.com/topics/h8YKVKx21t/cve-2022-24990Third Party Advisory
- https://forum.terra-master.com/en/viewforum.php?f=28Release Notes
- https://github.com/0xf4n9x/CVE-2022-24990Exploit
- https://octagon.net/blog/2022/03/07/cve-2022-24990-terrmaster-tos-unauthenticated-remote-command-execution-via-php-object-instantiationExploit
- https://packetstormsecurity.com/files/172904Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.