Vulnerabilities > Terra Master > Terramaster Operating System > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-08-20 CVE-2022-24989 Injection vulnerability in Terra-Master Terramaster Operating System
TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI.
network
low complexity
terra-master CWE-74
critical
9.8
2020-12-23 CVE-2020-35665 OS Command Injection vulnerability in Terra-Master Terramaster Operating System 3.0.33/3.1.03/4.2.06
An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation.
network
low complexity
terra-master CWE-78
critical
9.8
2018-11-27 CVE-2018-13336 OS Command Injection vulnerability in Terra-Master Terramaster Operating System 3.1.03
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "pwd" parameter during user creation.
network
low complexity
terra-master CWE-78
critical
9.8
2018-11-27 CVE-2018-13338 OS Command Injection vulnerability in Terra-Master Terramaster Operating System 3.1.03
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "username" parameter during user creation.
network
low complexity
terra-master CWE-78
critical
9.8
2018-11-27 CVE-2018-13350 SQL Injection vulnerability in Terra-Master Terramaster Operating System 3.1.03
SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter.
network
low complexity
terra-master CWE-89
critical
9.8
2018-11-27 CVE-2018-13354 OS Command Injection vulnerability in Terra-Master Terramaster Operating System 3.1.03
System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter.
network
low complexity
terra-master CWE-78
critical
9.8
2017-09-15 CVE-2017-9328 OS Command Injection vulnerability in Terra-Master Terramaster Operating System 3.0.33
Shell metacharacter injection vulnerability in /usr/www/include/ajax/GetTest.php in TerraMaster TOS before 3.0.34 leads to remote code execution as root.
network
low complexity
terra-master CWE-78
critical
9.8