Terra-master
Terra-master TOS: vulnerabilidades y CVE
Terra-master TOS tiene 15 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses0
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-34539 | Crítica (9.4) | 0.52% | — | 14 jun 2024 | Hardcoded credentials in TerraMaster TOS firmware through 5.1 allow a remote attacker to successfully login to the mail or webmail server. These credentials can also be used to login to the administration panel and to… |
| CVE-2021-45842 | Alta (7.5) | 2.4% | — | 25 abr 2022 | It is possible to obtain the first administrator's hash set up in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) on the system as well as other information such as MAC address, internal IP address etc. by… |
| CVE-2021-45841 | Alta (8.1) | 8.4% | — | 25 abr 2022 | In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the user's password hash. Guest users (disabled by default) can be abused… |
| CVE-2021-45840 | Crítica (9.8) | 3.9% | — | 25 abr 2022 | It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending specifically crafted input to /tos/index.php?app/app_start_stop. |
| CVE-2021-45839 | Media (6.5) | 9.9% | — | 25 abr 2022 | It is possible to obtain the first administrator's hash set up on the system in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) as well as other information such as MAC address, internal IP address etc. by… |
| CVE-2021-45837 | Crítica (9.8) | 16% | — | 25 abr 2022 | It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically crafted input to /tos/index.php?app/del. |
| CVE-2021-45836 | Alta (8.8) | 2.5% | — | 25 abr 2022 | An authenticated attacker can execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by injecting a maliciously crafted input in the request through /tos/index.php?app/hand_app. |
| CVE-2020-15568 | Crítica (9.8) | 29% | — | 30 ene 2021 | TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a… |
| CVE-2020-29189 | Alta (8.1) | 1.9% | — | 24 dic 2020 | Incorrect Access Control vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated attackers to bypass read-only restriction and obtain full access to any folder within the NAS |
| CVE-2020-28190 | Media (5.9) | 0.79% | — | 24 dic 2020 | TerraMaster TOS <= 4.2.06 was found to check for updates (of both system and applications) via an insecure channel (HTTP). Man-in-the-middle attackers are able to intercept these requests and serve a weaponized/infected… |
| CVE-2020-28188 | Crítica (9.8) | 97% | — | 24 dic 2020 | Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter. |
| CVE-2020-28187 | Crítica (9.8) | 16% | — | 24 dic 2020 | Multiple directory traversal vulnerabilities in TerraMaster TOS <= 4.2.06 allow remote authenticated attackers to read, edit or delete any file within the filesystem via the (1) filename parameter to… |
| CVE-2020-28186 | Alta (7.3) | 4.1% | — | 24 dic 2020 | Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functionality and achieve account takeover. |
| CVE-2020-28185 | Media (5.3) | 18% | — | 24 dic 2020 | User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system via the username parameter to wizard/initialise.php. |
| CVE-2020-28184 | Media (5.4) | 0.87% | — | 24 dic 2020 | Cross-site scripting (XSS) vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated users to inject arbitrary web script or HTML via the mod parameter to /module/index.php. |