VYPR

Terramaster Operating System

by Terra Master

CVEs (28)

  • CVE-2022-24990HigKEVFeb 7, 2023
    risk 0.76cvss 7.5epss 0.83

    TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.

  • CVE-2020-35665CriDec 23, 2020
    risk 0.73cvss 9.8epss 0.78

    An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation.

  • CVE-2022-24989CriAug 20, 2023
    risk 0.69cvss 9.8epss 0.32

    TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI. (Shell metacharacters can be placed in raidtype because popen is used…

  • CVE-2018-13354CriNov 27, 2018
    risk 0.66cvss 9.8epss 0.23

    System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter.

  • CVE-2018-13350CriNov 27, 2018
    risk 0.65cvss 9.8epss 0.17

    SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter.

  • CVE-2018-13338CriNov 27, 2018
    risk 0.65cvss 9.8epss 0.10

    System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "username" parameter during user creation.

  • CVE-2018-13336CriNov 27, 2018
    risk 0.64cvss 9.8epss 0.09

    System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "pwd" parameter during user creation.

  • CVE-2017-9328CriSep 15, 2017
    risk 0.64cvss 9.8epss 0.07

    Shell metacharacter injection vulnerability in /usr/www/include/ajax/GetTest.php in TerraMaster TOS before 3.0.34 leads to remote code execution as root.

  • CVE-2018-13359HigNov 27, 2018
    risk 0.59cvss 8.8epss 0.20

    Cross-site scripting in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "modgroup" parameter.

  • CVE-2018-13358HigNov 27, 2018
    risk 0.59cvss 8.8epss 0.25

    System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "checkName" parameter.

  • CVE-2018-13418HigNov 27, 2018
    risk 0.58cvss 8.8epss 0.05

    System command injection in ajaxdata.php in TerraMaster TOS 3.1.03 allows attackers to execute system commands via the "newname" parameter.

  • CVE-2018-13353HigNov 27, 2018
    risk 0.58cvss 8.8epss 0.06

    System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute commands via the "checkport" parameter.

  • CVE-2018-13356HigNov 27, 2018
    risk 0.57cvss 8.8epss 0.02

    Incorrect access control on ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to elevate user permissions.

  • CVE-2018-13352HigNov 27, 2018
    risk 0.49cvss 7.5epss 0.02

    Session Exposure in the web application for TerraMaster TOS version 3.1.03 allows attackers to view active session tokens in a world-readable directory.

  • CVE-2018-13332HigNov 27, 2018
    risk 0.49cvss 7.5epss 0.02

    Directory Traversal in the explorer application in TerraMaster TOS version 3.1.03 allows attackers to upload files to arbitrary locations via the "path" URL parameter.

  • CVE-2018-13330HigNov 27, 2018
    risk 0.47cvss 7.2epss 0.08

    System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands during group creation via the "groupname" parameter.

  • CVE-2018-13355MedNov 27, 2018
    risk 0.42cvss 6.5epss 0.01

    Incorrect access controls in ajaxdata.php in TerraMaster TOS version 3.1.03 allow attackers to create user groups without proper authorization.

  • CVE-2018-13360MedNov 27, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting in Text Editor in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "filename" URL parameter.

  • CVE-2018-13349MedNov 27, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting in the web application taskbar in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the user's username.

  • CVE-2018-13333MedNov 27, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting in File Manager in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript in the permissions window by placing JavaScript in users' usernames.

Page 1 of 2