Description
Buffalo TeraStation NAS TS5400R firmware version 4.02-0.06 and prior contain an excessive file permissions vulnerability that allows authenticated attackers to read the /etc/shadow file by uploading and executing a PHP file through the webserver. Attackers can exploit world-readable permissions on /etc/shadow to retrieve hashed passwords for all configured accounts including root.
Problem types
CWE-732 Incorrect Permission Assignment for Critical Resource
Product status
Any version
Credits
Victor A. Morales, Senior Pentester Team Leader, GM Sectec, Corp
Omar Crespo, Pentester, GM Sectec, Corp.
VulnCheck
References
buffaloamericas.com/
www.vulncheck.com/...file-permissions-information-disclosure