CVE-2021-30127
Last modified
CVE-2021-30127 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. TerraMaster F2-210 devices through 2021-04-03 use UPnP to make the admin web server accessible over the Internet on TCP port 8181, which is arguably inconsistent with the "It is only available on the local network" documentation. NOTE: manually editing /etc/upnp.json provides a partial but undocumented workaround.. EPSS estimates a 0.85% chance of exploitation in the next 30 days.
Description
TerraMaster F2-210 devices through 2021-04-03 use UPnP to make the admin web server accessible over the Internet on TCP port 8181, which is arguably inconsistent with the "It is only available on the local network" documentation. NOTE: manually editing /etc/upnp.json provides a partial but undocumented workaround.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Terra-Master | F2-210 Firmware | <= 2021-04-03 |
References
- https://kn100.me/terramaster-nas-exposing-itself-over-upnp/Exploit, Third Party Advisory
- https://news.ycombinator.com/item?id=26681984Issue Tracking, Third Party Advisory
- https://kn100.me/terramaster-nas-exposing-itself-over-upnp/Exploit, Third Party Advisory
- https://news.ycombinator.com/item?id=26681984Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-30127?
How severe is CVE-2021-30127?
How do I fix CVE-2021-30127?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-30120Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA r…7.5
- CVE-2021-30121Semi-authenticated local file inclusion The contents of arbi…6.5
- CVE-2021-30123FFmpeg <=4.3 contains a buffer overflow vulnerability in lib…8.8
- CVE-2021-30124The unofficial vscode-phpmd (aka PHP Mess Detector) extensio…9.8
- CVE-2021-30125Jamf Pro before 10.28.0 allows XSS related to inventory hist…6.1
- CVE-2021-30126Lightmeter ControlCenter 1.1.0 through 1.5.x before 1.5.1 al…6.5
- CVE-2021-30128Apache OFBiz has unsafe deserialization prior to 17.12.07 ve…9.8
- CVE-2021-30129A vulnerability in sshd-core of Apache Mina SSHD allows an a…6.5
- CVE-2021-3013ripgrep before 13 on Windows allows attackers to trigger exe…9.8
- CVE-2021-30130phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA …7.5
- CVE-2021-30132Cloudera Manager 7.2.4 has Incorrect Access Control, allowin…9.8
- CVE-2021-30133A cross-site scripting (XSS) vulnerability in CloverDX Serve…6.1
Are you affected by CVE-2021-30127?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
