S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-24990 Scanner

CVE-2022-24990 scanner - Information Disclosure vulnerability in TerraMaster NAS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2022-24990
7.5
CVSScritical
Exploitable remotely over the internet · no authentication required.

TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

TerraMaster NAS is a network-attached storage device designed for small to medium-sized businesses and home users who require a secure and reliable way to store and share files. This device is perfect for those looking for a centralized storage solution that can be accessed from any device over the internet. The TerraMaster NAS is equipped with various features such as data backup and synchronization, RAID support, and multimedia streaming to multimedia devices.

The TerraMaster NAS 4.2.29 and earlier versions have been found vulnerable to CVE-2022-24990. The vulnerability allows remote attackers to discover the administrative password using a simple method: sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response. This vulnerability can be exploited by attackers to gain access to the TerraMaster NAS and potentially steal sensitive data.

Exploiting this vulnerability can lead to serious consequences, such as unauthorized access to confidential data and personal information. Attackers can also gain control of the network that the TerraMaster NAS is on and use it for malicious purposes like launching DDoS attacks.

It's crucial to stay up-to-date with the latest vulnerabilities and security issues that may affect your digital assets. Thanks to the pro features of the s4e.io platform, you can easily and quickly learn about vulnerabilities in your digital assets. s4e.io can help you scan for vulnerabilities in your digital assets and provide actionable recommendations to keep your data safe from potential threats. Don't wait until it's too late, act now to protect your digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Update your TerraMaster NAS to the latest firmware version as soon as possible.
  • Set a strong and complex password for the administrative account.
  • Disable remote access when not needed.
  • Block incoming traffic from unknown IP addresses and only allow access from trusted sources.
  • Regularly monitor and review logs and alerts related to the TerraMaster NAS to detect any suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-24990 scanner - Information Disclosure vulnerability in TerraMaster NAS | S4E