EXPOSURES › CVE-2022-24990
CVE-2022-24990
CRITICAL ⌖ ON CISA KEV · EXPLOITEDTerraMaster OS allows unauthenticated remote command execution, enabling attackers to execute arbitrary commands on the system.
This vulnerability allows unauthenticated attackers to execute arbitrary commands on TerraMaster OS endpoints, directly enabling ransomware deployment and system compromise. For DIB organizations, this represents a critical exposure where an unpatched, actively exploited flaw in a NAS/OS product could lead to data theft, ransomware infection, and compliance violations. Organizations must verify patch levels on all TerraMaster devices and isolate or replace unpatched systems immediately.
Shame score — The vendor shipped an OS with a critical remote code execution flaw that was actively exploited in the wild to deploy ransomware, demonstrating severe negligence in patch management and security engineering.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
TerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint.