VYPR

FS-210

by Terra Master

CVEs (10)

  • CVE-2021-45837CriApr 25, 2022
    risk 0.68cvss 9.8epss 0.16

    It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically crafted input to /tos/index.php?app/del.

  • CVE-2021-45840CriApr 25, 2022
    risk 0.64cvss 9.8epss 0.04

    It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending specifically crafted input to /tos/index.php?app/app_start_stop.

  • CVE-2021-45836HigApr 25, 2022
    risk 0.57cvss 8.8epss 0.02

    An authenticated attacker can execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by injecting a maliciously crafted input in the request through /tos/index.php?app/hand_app.

  • CVE-2019-18195HigOct 28, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered on TerraMaster FS-210 4.0.19 devices. Normal users can use 1.user.php for privilege elevation.

  • CVE-2021-45842HigApr 25, 2022
    risk 0.49cvss 7.5epss 0.02

    It is possible to obtain the first administrator's hash set up in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) on the system as well as other information such as MAC address, internal IP address etc. by performing a request to the /module/api.php?mobile/wapNasIPS…

  • CVE-2019-18385HigOct 23, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the include/makecvs.php?Event= substring.

  • CVE-2019-18383HigOct 23, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on TerraMaster FS-210 4.0.19 devices. One can download backup files remotely from terramaster_TNAS-00E43A_config_backup.bin without permission.

  • CVE-2021-30127HigApr 3, 2021
    risk 0.48cvss 7.3epss 0.01

    TerraMaster F2-210 devices through 2021-04-03 use UPnP to make the admin web server accessible over the Internet on TCP port 8181, which is arguably inconsistent with the "It is only available on the local network" documentation. NOTE: manually editing /etc/upnp.json provides a…

  • CVE-2021-45839MedApr 25, 2022
    risk 0.46cvss 6.5epss 0.10

    It is possible to obtain the first administrator's hash set up on the system in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) as well as other information such as MAC address, internal IP address etc. by performing a request to the /module/api.php?mobile/webNasIPS…

  • CVE-2019-18384MedOct 23, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered on TerraMaster FS-210 4.0.19 devices. An authenticated remote non-administrative user can read unauthorized shared files, as demonstrated by the filename=*public*%25252Fadmin_OnlyRead.txt substring.