Vulnerabilities > Terra Master > High

DATE CVE VULNERABILITY TITLE RISK
2023-02-07 CVE-2022-24990 Missing Authentication for Critical Function vulnerability in Terra-Master Terramaster Operating System
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.
network
low complexity
terra-master CWE-306
7.5
2022-04-25 CVE-2021-45836 Unspecified vulnerability in Terra-Master TOS 4.2.152107141517
An authenticated attacker can execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by injecting a maliciously crafted input in the request through /tos/index.php?app/hand_app.
network
low complexity
terra-master
8.8
2022-04-25 CVE-2021-45841 Use of Hard-coded Credentials vulnerability in Terra-Master TOS 4.2.152107141517
In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the user's password hash.
network
high complexity
terra-master CWE-798
8.1
2022-04-25 CVE-2021-45842 Unspecified vulnerability in Terra-Master TOS 4.2.152107141517
It is possible to obtain the first administrator's hash set up in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) on the system as well as other information such as MAC address, internal IP address etc.
network
low complexity
terra-master
7.5
2021-04-03 CVE-2021-30127 Unspecified vulnerability in Terra-Master F2-210 Firmware 20210403/4.0.19
TerraMaster F2-210 devices through 2021-04-03 use UPnP to make the admin web server accessible over the Internet on TCP port 8181, which is arguably inconsistent with the "It is only available on the local network" documentation.
network
low complexity
terra-master
7.3
2020-12-24 CVE-2020-29189 Unspecified vulnerability in Terra-Master TOS
Incorrect Access Control vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated attackers to bypass read-only restriction and obtain full access to any folder within the NAS
network
low complexity
terra-master
8.1
2020-12-24 CVE-2020-28186 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Terra-Master TOS
Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functionality and achieve account takeover.
network
low complexity
terra-master CWE-640
7.3
2019-10-28 CVE-2019-18195 Unspecified vulnerability in Terra-Master F2-210 Firmware 4.0.19
An issue was discovered on TerraMaster FS-210 4.0.19 devices.
network
low complexity
terra-master
8.8
2019-10-23 CVE-2019-18385 Information Exposure Through Log Files vulnerability in Terra-Master Fs-210 Firmware 4.0.19
An issue was discovered on TerraMaster FS-210 4.0.19 devices.
network
low complexity
terra-master CWE-532
7.5
2019-10-23 CVE-2019-18383 Missing Authorization vulnerability in Terra-Master Fs-210 Firmware 4.0.19
An issue was discovered on TerraMaster FS-210 4.0.19 devices.
network
low complexity
terra-master CWE-862
7.5