Terramaster · Terramaster F4-210 · CVE-2021-45842
**Name of the Vulnerable Software and Affected Versions**
Terramaster F4-210, F2-210 TOS versions 4.2.15-2107141517
**Description**
The issue allows an attacker to obtain sensitive information, including the first administrator's hash, MAC address, and internal IP address, by sending a request to the "/module/api.php?mobile/wapNasIPS" endpoint.
**Recommendations**
For Terramaster F4-210, F2-210 TOS versions 4.2.15-2107141517, as a temporary workaround, consider restricting access to the "/module/api.php?mobile/wapNasIPS" endpoint until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.