Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Buffalo TeraStation TS5400R Excessive File Permissions Information Disclosure
Vulnerability Description
Buffalo TeraStation NAS TS5400R firmware version 4.02-0.06 and prior contain an excessive file permissions vulnerability that allows authenticated attackers to read the /etc/shadow file by uploading and executing a PHP file through the webserver. Attackers can exploit world-readable permissions on /etc/shadow to retrieve hashed passwords for all configured accounts including root.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
关键资源的不正确权限授予
Vulnerability Title
Buffalo TeraStation NAS TS5400R 安全漏洞
Vulnerability Description
Buffalo TeraStation NAS TS5400R是日本Buffalo公司的一款机架式网络附加存储设备。 Buffalo TeraStation NAS TS5400R 4.02-0.06及之前版本存在安全漏洞,该漏洞源于文件权限设置不当,可能导致攻击者读取/etc/shadow文件并检索哈希密码。
CVSS Information
N/A
Vulnerability Type
N/A