CVE-2020-28188
CRITICAL EXPLOITED IN THE WILD RANSOMWARE NUCLEITerraMaster TOS <= 4.2.06 - Unauthenticated Remote Code Execution via Event Parameter
Title source: llmExploitation Summary
CVE-2020-28188 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io), including in ransomware campaigns.
EIP tracks 1 public exploit, including a Metasploit module exploits/linux/http/terramaster_unauth_rce_cve_2020_35665.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated RCE vulnerability in TerraMaster TOS via shell metacharacter injection in the Event parameter of the makecvs.php endpoint. It uploads a webshell and executes commands or payloads under the web application's privileges.
Description
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.
Exploits (1)
This Metasploit module exploits an unauthenticated RCE vulnerability in TerraMaster TOS via shell metacharacter injection in the Event parameter of the makecvs.php endpoint. It uploads a webshell and executes commands or payloads under the web application's privileges.
Nuclei Templates (1)
"terramaster" && header="tos"
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H