Showing 4 vulnerabilities on this page for tos

Signals CISA KEV Ransomware Nuclei
TerraMaster vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Terramaster index.php app/del Vulnerability

It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically crafted input to /tos/index.php?app/del.

Apr 25, 2022
CVSS9.8v3.1EPSS15.7%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

TerraMaster tos Improper Control of Dynamically-Managed Code Resources

TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter.

CWE-78CWE-913Jan 30, 20211 related artifact
CVSS9.8v3.1EPSS28.5%PoCs2SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

TerraMaster TOS <= 4.2.06 Unauthenticated User Enumeration

User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system via the username parameter to wizard/initialise.php.

Dec 24, 20201 related artifact
CVSS5.3v3.1EPSS18.7%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

TerraMaster tos Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.

CWE-78Dec 24, 20201 related artifact
CVSS9.8v3.1EPSS96.6%PoCs1SignalsNot listed in CISA KEVKnown ransomware use1 Nuclei templateSTIX