Skip to content
COOEY

EXPOSURES › CVE-2022-24990

CVE-2022-24990

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-02-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-24990 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

TerraMaster OS allows unauthenticated remote command execution, enabling attackers to execute arbitrary commands on the system.

This vulnerability allows unauthenticated attackers to execute arbitrary commands on TerraMaster OS endpoints, directly enabling ransomware deployment and system compromise. For DIB organizations, this represents a critical exposure where an unpatched, actively exploited flaw in a NAS/OS product could lead to data theft, ransomware infection, and compliance violations. Organizations must verify patch levels on all TerraMaster devices and isolate or replace unpatched systems immediately.

Shame score — The vendor shipped an OS with a critical remote code execution flaw that was actively exploited in the wild to deploy ransomware, demonstrating severe negligence in patch management and security engineering.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

TerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.