Page 1 of 1

Patch TOS_PATCH_1.31

Posted: 18 Feb 2022, 16:12
by TMSupport
TOS Patch 1.31 Release Notes

Applicable model: All TNAS models

Applicable version: TOS 4.2.28

This patch includes following bug fixes for the previous version:
1. Fixed a security vulnerability in TNAS Mobile login verification.

Note:
This patch package has compatibility issues with the current version of TNAS mobile (Android 2.4.15/IOS 2.4.12), and there may be cases where devices cannot be added and cannot be logged in. Please decide whether to update the patch according to the situation. The new TNAS mobile version will fix this issue and is expected to be released in March.

Download link:
PATCH_ARM_1.31
PATCH_X64_1.31

How to install the patch?

1. Go to TOS> Control Panel> General Settings> Update & Restore, and click “Manual Update”;
2. Click "Browse" to select the downloaded patch package;
3. Click "Apply";
4. Restart the system.

Re: Patch TOS_PATCH_1.31

Posted: 18 Feb 2022, 17:49
by crisisacting
TMSupport wrote: 18 Feb 2022, 16:12 1. Fixed a security vulnerability in TNAS Mobile login verification.
So, not necessary for those that don't have TNAS Mobile enabled, correct?

Re: Patch TOS_PATCH_1.31

Posted: 18 Feb 2022, 18:00
by TMSupport
crisisacting wrote: 18 Feb 2022, 17:49
TMSupport wrote: 18 Feb 2022, 16:12 1. Fixed a security vulnerability in TNAS Mobile login verification.
So, not necessary for those that don't have TNAS Mobile enabled, correct?
Correct the previous answer, for safety, please update as much as possible.

Re: Patch TOS_PATCH_1.31

Posted: 22 Feb 2022, 01:08
by Gandalf1369
Has anyone who is running Docker, along with several Docker containers, installed this patch?? If yes, any problems getting the containers started again?

Re: Patch TOS_PATCH_1.31

Posted: 22 Feb 2022, 02:48
by sports_wook
No issue here with docker containers after applying the patch

Re: Patch TOS_PATCH_1.31

Posted: 23 Feb 2022, 16:21
by sianderson
TMSupport wrote: 18 Feb 2022, 18:00 for safety, please update as much as possible.
not technically true, atleast one of your previous patches fixed issues so functions worked, whereas an unpatched version didnt allow remote access, your patch then allowed an increased potential that it could be sucessfully attacked so if you didnt need remote access you were safer to not install the patch, but swings and roundabouts