CVE detail
CVE-2022-24989 — CVE-2022-24989
Published 2023-08-20 · Modified 2026-06-17 · Vendor terra-master · Product terramaster_operating_system · Source nvd
CRITICAL
severity
CVSS-derived band
0.3188
EPSS probability
exploitation probability, 30d
98.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI. (Shell metacharacters can be placed in raidtype because popen is used without any sanitization.) The credentials from CVE-2022-24990 exploitation can be used.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References