Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An Incorrect Symlink Follow vulnerability exists in multiple Yottamaster NAS devices, including DM2 (version equal to or prior to V1.9.12), DM3 (version equal to or prior to V1.9.12), and DM200 (version equal to or prior to V1.2.23) that could be exploited by attackers to leak or tamper with the internal file system. Attackers can format a USB drive to ext4, create a symbolic link to its root directory, insert the drive into the NAS device's slot, then access the USB drive's symlink directory mounted on the NAS to obtain all files within the NAS system and tamper with those files.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Yottamaster多款产品 安全漏洞
Vulnerability Description
Yottamaster DM2等都是Yottamaster公司的一款私有云硬盘盒。 Yottamaster多款产品存在安全漏洞,该漏洞源于符号链接跟随不正确,可能导致泄露或篡改内部文件系统。以下产品及版本受到影响:DM2 V1.9.12及之前版本、DM3 V1.9.12及之前版本和DM200 V1.2.23及之前版本。
CVSS Information
N/A
Vulnerability Type
N/A