Vulnerabilities > Terra Master > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-08-20 CVE-2022-24989 Injection vulnerability in Terra-Master Terramaster Operating System
TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI.
network
low complexity
terra-master CWE-74
critical
9.8
2022-04-25 CVE-2021-45837 Unspecified vulnerability in Terra-Master TOS 4.2.152107141517
It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically crafted input to /tos/index.php?app/del.
network
low complexity
terra-master
critical
9.8
2022-04-25 CVE-2021-45840 Unspecified vulnerability in Terra-Master TOS 4.2.152107141517
It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending specifically crafted input to /tos/index.php?app/app_start_stop.
network
low complexity
terra-master
critical
9.8
2021-01-30 CVE-2020-15568 Improper Control of Dynamically-Managed Code Resources vulnerability in Terra-Master TOS
TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root.
network
low complexity
terra-master CWE-913
critical
9.8
2020-12-24 CVE-2020-28188 OS Command Injection vulnerability in Terra-Master TOS
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.
network
low complexity
terra-master CWE-78
critical
9.8
2020-12-24 CVE-2020-28187 Path Traversal vulnerability in Terra-Master TOS
Multiple directory traversal vulnerabilities in TerraMaster TOS <= 4.2.06 allow remote authenticated attackers to read, edit or delete any file within the filesystem via the (1) filename parameter to /tos/index.php?editor/fileGet, Event parameter to /include/ajax/logtable.php, or opt parameter to /include/core/index.php.
network
low complexity
terra-master CWE-22
critical
9.8
2020-12-23 CVE-2020-35665 OS Command Injection vulnerability in Terra-Master Terramaster Operating System 3.0.33/3.1.03/4.2.06
An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation.
network
low complexity
terra-master CWE-78
critical
9.8
2018-11-27 CVE-2018-13354 OS Command Injection vulnerability in Terra-Master Terramaster Operating System 3.1.03
System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter.
network
low complexity
terra-master CWE-78
critical
9.8
2018-11-27 CVE-2018-13350 SQL Injection vulnerability in Terra-Master Terramaster Operating System 3.1.03
SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter.
network
low complexity
terra-master CWE-89
critical
9.8
2018-11-27 CVE-2018-13338 OS Command Injection vulnerability in Terra-Master Terramaster Operating System 3.1.03
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "username" parameter during user creation.
network
low complexity
terra-master CWE-78
critical
9.8