CRITICAL

CVE-2022-24989

CVSS v3

9.8

CRITICAL

EPSS Score

82.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI. (Shell metacharacters can be placed in raidtype because popen is used without any sanitization.) The credentials from CVE-2022-24990 exploitation can be used.

Technical details

Published
8/20/2023

Frequently asked questions

What is CVE-2022-24989?

TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI. (Shell metacharacters can be placed in raidtype because popen is used without any sanitization.) The credentials from CVE-2022-24990 exploitation can be used.

Is CVE-2022-24989 actively exploited?

Active exploitation of CVE-2022-24989 has not been confirmed. The EPSS score is 82.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-24989?

CVE-2022-24989 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2022-24989 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.