- POC for CVE-2022-24990: TerraMaster TOS unauthenticated remote command execution via PHP Object Instantiation.
- create by antx at 2022-04-12.
- The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
- The vulnerability exists due to improper input validation in the webNasIPS component in the api.php script. A remote unauthenticated attacker can pass specially crafted data to the application and execute arbitrary commands on the target system.
- Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
- attackComplexity: LOW
- attackVector: NETWORK
- availabilityImpact: HIGH
- confidentialityImpact: HIGH
- integrityImpact: HIGH
- privilegesRequired: NONE
- scope: UNCHANGED
- userInteraction: NONE
- version: 3.1
- baseScore: 10.0
- baseSeverity: CRITICAL
- TerraMaster TOS
- < 4.2.30
- All of 4.1.x
- Ref-Source
- CVE
- CNVD
- CNNVD
- Ref-Poc-Engine