Yottamaster File Read/Tamper Information Vendor: Yottamaster Affected Products: - DM2 ≤ V1.9.12 - DM3 ≤ V1.9.12 - DM200 ≤ V1.2.23 Vendor Homepage: https://yottamaster.com/ Vendor Contact Information: supports@yottamaster.com Description A vulnerability exists in multiple Yottamaster NAS devices, including DM2 (version equal to or prior to V1.9.12), DM3 (version equal to or prior to V1.9.12), and DM200 (version equal to or prior to V1.2.23) that could be exploited by attackers to leak or tamper with the internal file system. This vulnerability stems from lax checks on symbolic links within external USB devices. Attackers can create a symlink to its root directory, insert the drive into the NAS device's slot, then access the USB drive's symlink directory mounted on the NAS to obtain all files within the NAS system and tamper with those files.