CVE-2022-24990:通过 PHP 对象实例化在 TerraMaster TOS 上实现未认证远程命令执行
pwn.ai | 漏洞 | CVE-2022-24990 | #pre-auth-rce | #vulnerability-chain | #terramaster | #cve-2022-24990 | #nas | #php-object-instantiation
摘要
Octagon Networks 复盘 TerraMaster TOS 4.2.29 漏洞链:PHP 对象实例化缺陷与签名校验绕过相结合,实现 NAS 设备上未认证的远程 root 命令执行。
- CVE
- CVE-2022-24990
- 发布时间
- 收录时间
Skip to content