Exploits / Vulnerability Discovered : 2022-09-20 |
Type : webapps |
Platform : hardware
This exploit / vulnerability Buffalo terastation network attached storage (nas) 1.66 authentication bypass is for educational purposes only and if it is used you will do on your own risk!
An authentication bypass vulnerability found within the web interface of a Buffalo TeraStation Series Network Attached Storage (NAS) device, allows an unauthenticated malicious actor to gain administrative privileges.
The web interface can be accessed via port 80 or 443 via a web browser. Once accessed you will be presented with a login page, that requires a username and password to gain authentication to the NAS.
Using a proxy tool to intercept the request and responses, it was possible re-intercept the response and modify the JSON data, contained within the body.
If you modify the "success" to 'true' and change "Pagemode" to '0', this will grant you authentication with administrator privileges, to the NAS.