Get Support
Forums
Knowledge Base
Data Recovery
Security Notices
Downloads
Warranty Information
Find and download the latest product firmware, utility or driver.
Partner Program
Red Rewards
Deal Registration
Case Studies & White Papers
Webinars
Helpful Tips & Articles
About Buffalo
Buffalo Compliance Information
Trademarks
Legal
Press Releases
Summary
A vulnerability in the /nasapi endpoint of Buffalo NAS devices allows unauthenticated or guest-level users to enumerate valid usernames and their associated privilege roles.
Affected Supported TeraStations All NAS products
Impact: The following information can be obtained: Username, User ID, Category, Role, Description, Quota, Groups, Primary Group
Recommended Action: To mitigate this risk immediately, it is highly recommended to disable the guest user account. This prevents unauthenticated users from accessing the /nasapi endpoint used to trigger the enumeration.
Back to Security Notices
This site uses cookies in order to improve your user experience and to provide content tailored specifically to your interest. By continuing to browse our site, you agree to our use of cookies. You can view our Privacy Notice here.