CVE Vulnerabilities

CVE-2021-30127

Published: Apr 03, 2021 | Modified: Jul 12, 2022
CVSS 3.x
7.3
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

TerraMaster F2-210 devices through 2021-04-03 use UPnP to make the admin web server accessible over the Internet on TCP port 8181, which is arguably inconsistent with the It is only available on the local network documentation. NOTE: manually editing /etc/upnp.json provides a partial but undocumented workaround.

Affected Software

Name Vendor Start Version End Version
F2-210_firmware Terra-master * 2021-04-03 (including)

References