Loading
Generated remediation guidance and an executive summary. No account required.
In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the user's password hash. Guest users (disabled by default) can be abused using a null/empty hash and allow an unauthenticated attacker to login as guest.
Use CWE-287, Terra-Master vendor hub and Tos product page to widen CVE-2021-45841 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-45840, CVE-2021-45837 and CVE-2020-15568 for nearby disclosures in the same product family.