Vulnerabilities > Terra Master > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-08-20 CVE-2022-24989 Injection vulnerability in Terra-Master Terramaster Operating System
TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI.
network
low complexity
terra-master CWE-74
critical
9.8
2022-04-25 CVE-2021-45836 Unspecified vulnerability in Terra-Master TOS 4.2.152107141517
An authenticated attacker can execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by injecting a maliciously crafted input in the request through /tos/index.php?app/hand_app.
network
low complexity
terra-master
critical
9.0
2022-04-25 CVE-2021-45837 Unspecified vulnerability in Terra-Master TOS 4.2.152107141517
It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically crafted input to /tos/index.php?app/del.
network
low complexity
terra-master
critical
9.8
2022-04-25 CVE-2021-45840 Unspecified vulnerability in Terra-Master TOS 4.2.152107141517
It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending specifically crafted input to /tos/index.php?app/app_start_stop.
network
low complexity
terra-master
critical
10.0
2021-01-30 CVE-2020-15568 OS Command Injection vulnerability in Terra-Master TOS
TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root.
network
low complexity
terra-master CWE-78
critical
10.0
2020-12-24 CVE-2020-28188 OS Command Injection vulnerability in Terra-Master TOS
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.
network
low complexity
terra-master CWE-78
critical
9.8
2020-12-24 CVE-2020-28187 Path Traversal vulnerability in Terra-Master TOS
Multiple directory traversal vulnerabilities in TerraMaster TOS <= 4.2.06 allow remote authenticated attackers to read, edit or delete any file within the filesystem via the (1) filename parameter to /tos/index.php?editor/fileGet, Event parameter to /include/ajax/logtable.php, or opt parameter to /include/core/index.php.
network
low complexity
terra-master CWE-22
critical
10.0
2020-12-23 CVE-2020-35665 OS Command Injection vulnerability in Terra-Master Terramaster Operating System 3.0.33/3.1.03/4.2.06
An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation.
network
low complexity
terra-master CWE-78
critical
9.8
2018-11-27 CVE-2018-13418 OS Command Injection vulnerability in Terra-Master Terramaster Operating System 3.1.03
System command injection in ajaxdata.php in TerraMaster TOS 3.1.03 allows attackers to execute system commands via the "newname" parameter.
network
low complexity
terra-master CWE-78
critical
9.0
2018-11-27 CVE-2018-13358 OS Command Injection vulnerability in Terra-Master Terramaster Operating System 3.1.03
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "checkName" parameter.
network
low complexity
terra-master CWE-78
critical
9.0