CVE-2024-34539
- EPSS 0.52%
- Veröffentlicht 14.06.2024 15:15:50
- Zuletzt bearbeitet 21.11.2024 09:18:53
Hardcoded credentials in TerraMaster TOS firmware through 5.1 allow a remote attacker to successfully login to the mail or webmail server. These credentials can also be used to login to the administration panel and to perform privileged actions.
CVE-2022-24989
- EPSS 82.11%
- Veröffentlicht 20.08.2023 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:51:31
TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI. (Shell metacharacters can be placed in raidtype...
CVE-2022-24990
- EPSS 94.4%
- Veröffentlicht 07.02.2023 18:15:09
- Zuletzt bearbeitet 07.11.2025 19:02:38
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.
- EPSS 89.25%
- Veröffentlicht 23.12.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:27:47
An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation.
- EPSS 11.98%
- Veröffentlicht 27.11.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 03:47:04
System command injection in ajaxdata.php in TerraMaster TOS 3.1.03 allows attackers to execute system commands via the "newname" parameter.
CVE-2018-13361
- EPSS 0.32%
- Veröffentlicht 27.11.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 03:46:57
User enumeration in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to list all system users via the "modgroup" parameter.
CVE-2018-13360
- EPSS 0.24%
- Veröffentlicht 27.11.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 03:46:57
Cross-site scripting in Text Editor in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "filename" URL parameter.
CVE-2018-13359
- EPSS 0.61%
- Veröffentlicht 27.11.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 03:46:57
Cross-site scripting in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "modgroup" parameter.
CVE-2018-13352
- EPSS 0.32%
- Veröffentlicht 27.11.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:46:56
Session Exposure in the web application for TerraMaster TOS version 3.1.03 allows attackers to view active session tokens in a world-readable directory.
- EPSS 15.59%
- Veröffentlicht 27.11.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:46:57
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "checkName" parameter.