PT-2020-5870 · Terramaster · Terramaster Tos

·

CVE-2020-28188

·

Published

2020-12-24

·

Updated

2024-01-11

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: TerraMaster TOS versions <= 4.2.06
Description: The issue is related to the "Event" parameter in the /include/makecvs.php file of the TerraMaster TOS operating system, which fails to neutralize special elements used in operating system commands. This can be exploited by a remote attacker to execute arbitrary code. The vulnerability allows remote unauthenticated attackers to inject OS commands via the "Event" parameter in the /include/makecvs.php file.
Recommendations: For TerraMaster TOS versions <= 4.2.06, update to a version later than 4.2.06 to resolve the issue. As a temporary workaround, consider restricting access to the /include/makecvs.php file and the Event parameter to minimize the risk of exploitation.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01921
CVE-2020-28188

Affected Products

Terramaster Tos