CVE-2022-24990
TerraMaster TerraMaster OS
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.
- CVSS
- 7.5
- EPSS
- 83.5% 99.7% percentile
- CISA KEV
- Listed
- Published
- 2023.02.08