vendor:
TeraStation Series
by:
JORDAN GLOVER
9.8
CVSS
CRITICAL
Authentication Bypass
287
CWE
Product Name: TeraStation Series
Affected Version From: 1.66
Affected Version To: 1.66
Patch Exists: NO
Related CWE:
CPE: h:buffalo:terastation_series
Platforms Tested: Windows 10
2022
Buffalo TeraStation Network Attached Storage (NAS) 1.66 – Authentication Bypass
An authentication bypass vulnerability found within the web interface of a Buffalo TeraStation Series Network Attached Storage (NAS) device, allows an unauthenticated malicious actor to gain administrative privileges. Using a proxy tool to intercept the request and responses, it was possible re-intercept the response and modify the JSON data, contained within the body. If you modify the 'success' to 'true' and change 'Pagemode' to '0', this will grant you authentication with administrator privileges, to the NAS.
Mitigation:
Ensure that the web interface of the Buffalo TeraStation Series Network Attached Storage (NAS) device is not accessible from the public internet. If it is, ensure that the web interface is configured to use a secure authentication mechanism.