LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-24990: TerraMaster OS Remote Command Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 10, 2023
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Mar 3, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-24990 to its Known Exploited Vulnerabilities catalog on Feb 10, 2023, with a federal patch deadline of Mar 3, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

TerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint.

CVE-2022-24990 is a remote command execution vulnerability in TerraMaster OS that lets an unauthenticated user run commands on the target system. It matters because successful abuse can give attackers full control of the device, and this vulnerability has been used in ransomware campaigns. Teams that run TerraMaster storage appliances should treat it as high priority and confirm all details against the vendor advisory.

CISA lists the required action as applying updates per the vendor’s instructions. Public detail on exact affected builds is limited, so inventory and remediation must be validated against the official advisory for TerraMaster OS.

How it works

The flaw is classified as CWE-306, Missing Authentication for Critical Function. In this class of weakness, a sensitive operation that should require authentication can be reached without any credentials. An unauthenticated remote attacker can therefore invoke the vulnerable function and cause the system to execute arbitrary commands under the privileges of the TerraMaster OS process.

Because no authentication is enforced, the attacker does not need a valid account or session. Exploitation typically involves sending crafted requests to the exposed management interface of the appliance. Exact request formats and parameters are not described here; defenders should obtain those details only from the vendor advisory or trusted analysis that cites it. Once command execution is achieved, the attacker can install malware, create backdoors, or prepare the system for ransomware deployment—activity that has already been observed with this CVE.

Am I affected? How to find it in your systems

TerraMaster OS runs on TerraMaster network-attached storage (NAS) appliances commonly used for file sharing, backups, and media storage in small-to-medium environments. These devices are often reachable from the internal network and sometimes from the internet if remote-access features are enabled.

If the version cannot be confirmed or the advisory is unavailable, assume the device is vulnerable until proven otherwise and isolate it.

How to remediate

The primary remediation is to apply the vendor-supplied update that addresses CVE-2022-24990. Follow the installation steps exactly as documented by TerraMaster; CISA’s required action is simply “Apply updates per vendor instructions.” After patching, reboot if required and re-verify the version string.

Document the patch date and version for compliance and for any subsequent forensic review.

If you can't patch immediately

When an immediate update is not possible, apply compensating controls that reduce the attack surface of this unauthenticated command-execution class.

These measures do not eliminate the vulnerability; they only buy time until the official update can be installed.

If your data may have been exposed

Actively exploited vulnerabilities of this type frequently lead to data theft or ransomware encryption. If the appliance was reachable and unpatched during the period of known exploitation, treat any data stored on it as potentially compromised. Rotate credentials for accounts that had access to the device, review backup integrity, and follow your incident-response plan for containment and recovery. You can also run a free exposure scan of your email address against known breach data sets to determine whether associated credentials have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedTerraMaster · TerraMaster OS
WeaknessCWE-306
Added to CISA KEVFeb 10, 2023
Federal patch deadlineMar 3, 2023
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities