QID 730726

Date Published: 2023-02-15

QID 730726: TerraMaster NAS Remote Code Execution (RCE) Vulnerability

TerraMaster NAS devices running TOS version 4.2.29 suffer from a vulnerability which allows remote unauthenticated attackers to execute commands as root.

Affected Versions:
TerraMaster NAS devices running TOS version 4.2.29 and prior.

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable TerraMaster NAS devices by sending a GET request to module/api.php?mobile/webNasIPS endpoint.

Successful exploitation of the vulnerability may allow unauthenticated remote attackers to execute commands as root leading to complete system compromise.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Critical - 9.4 severity.
  • Solution
    Customers are advised to update to version 4.2.31 or later. For more information, please refer to TerraMaster TOS 4.2.31

    Vendor References

    CVEs related to QID 730726

    Software Advisories
    Advisory ID Software Component Link
    NA URL Logo forum.terra-master.com/en/viewtopic.php?f=28&t=3187&sid=5e91e1b153c8370a3c5dd43dc23a6bf4