Security Advisory

CVE-2022-24990

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-02-07 00:00:00
Last updated 2025-10-21 23:15:27
Assigner mitre
State PUBLISHED

Description

TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.