RULE(RULE ID:336793)

Rule General Information
Release Date: 2022-03-29
Rule Name: TerraMaster TOS Command Injection Vulnerability (CVE-2022-24989)
Severity:
CVE ID:
Rule Protection Details
Description: TerraMaster TOS could allow a remote authenticated attacker to execute arbitrary commands on the system, caused by a flaw in the createRaid module. By sending a specially-crafted command, an attacker could exploit this vulnerability to execute arbitrary commands as root on the system.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Others
Reference: https://www.redpacketsecurity.com/terramaster-tos-command-execution-cve-2022-24989/
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.terra-master.com/global