Record summary

CVE-2020-28185 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system via the username parameter to wizard/initialise.php.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 20, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMTerraMaster TOS < 4.2.06 - User EnumerationCVSS 5.3

User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system via the username parameter to wizard/initialise.php.

Impact

An attacker can enumerate valid usernames, potentially aiding in further attacks.

Remediation

Upgrade TerraMaster TOS to version 4.2.06 or later.

Authorspussycat0x
Template tagscve2020cveterramasterenumtosterra-mastervkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:o:terra-master:tos:*:*:*:*:*:*:*:*
FOFA: "TerraMaster" && header="TOS"
FOFA: "terramaster" && header="tos"

Source: ProjectDiscovery

References

3