CVE-2022-24990: TerraMaster TOS unauthenticated remote command execution via PHP Object Instantiation
pwn.ai | vulnerability | CVE-2022-24990 | #pre-auth-rce | #vulnerability-chain | #terramaster | #cve-2022-24990 | #nas | #php-object-instantiation
Summary
Octagon Networks' chain on TerraMaster TOS 4.2.29: a PHP object instantiation bug plus a signing-check bypass yields unauthenticated remote root command execution on NAS devices.
- CVE
- CVE-2022-24990
- Published
- Collected
Skip to content