
CVE-2022-24990 exploit tool with POC detection and EXP WebShell upload for TerraMaster NAS devices. Supports URL-based targeting and dual-mode operation.
A rapid exploitation tool for CVE-2022-24990. Novice code. Feel free to raise issues if you have any problems.
main -u http://127.0.0.1:8181 -t poc(exp)
Only detect information disclosure vulnerabilities.
Attempt to upload WebShell.
This tool is intended only for legally authorized enterprise security construction activities, such as internal offensive and defensive drills, vulnerability verification and retesting. If you need to test the usability of this tool, please set up your own target environment.
When using this tool for detection, you should ensure that the action complies with local laws and regulations and that sufficient authorization has been obtained. Do not use it against unauthorized targets.
If you engage in any illegal activities while using this tool, you shall bear the corresponding consequences. We shall not assume any legal or joint liability.