CVE-2021-30127
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/04/2021
Last modified:
12/07/2022
Description
TerraMaster F2-210 devices through 2021-04-03 use UPnP to make the admin web server accessible over the Internet on TCP port 8181, which is arguably inconsistent with the "It is only available on the local network" documentation. NOTE: manually editing /etc/upnp.json provides a partial but undocumented workaround.
Impact
Base Score 3.x
7.30
Severity 3.x
HIGH
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:terra-master:f2-210_firmware:*:*:*:*:*:*:*:* | 2021-04-03 (including) | |
| cpe:2.3:h:terra-master:f2-210:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



