Critical severity9.8NVD Advisory· Published Jan 30, 2021· Updated Jun 17, 2026
CVE-2020-15568
CVE-2020-15568
Description
TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:o:terra-master:tos:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:terra-master:tos:*:*:*:*:*:*:*:*range: <4.1.29
- (no CPE)range: <4.1.29
- TerraMaster/TOSdescription
Patches
Vulnerability mechanics
References
2- ssd-disclosure.com/ssd-advisory-terramaster-os-exportuser-php-remote-code-execution/nvdExploitThird Party Advisory
- help.terra-master.com/TOS/view/nvdProductVendor Advisory
News mentions
0No linked articles in our index yet.