An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the include/makecvs.php?Event= substring.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://github.com/gusrmsdlrh/CVE-Reserved3/blob/master/README.md | third party advisory exploit |