Vulnerability index

Browse CVEs

46 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Terramaster Operating System CRITICAL 9.8
CVE-2022-24989EPSS 32%

TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Objec…

Fix: 4.2.31+
Fix from $2,300 2023-08-20
Terramaster Operating System HIGH 7.5
CVE-2022-24990 KEVEPSS 83%

TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mo…

Fix: 4.2.31+
Fix from $1,950 2023-02-07
Tos CRITICAL 9.8
CVE-2021-45837EPSS 16%

It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically crafted in…

No fix yet
Fix from $2,300 2022-04-25
Tos CRITICAL 9.8
CVE-2021-45840

It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending specifically crafted inpu…

No fix yet
Fix from $2,300 2022-04-25
Tos HIGH 8.8
CVE-2021-45836

An authenticated attacker can execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by injecting a malicious…

No fix yet
Fix from $1,950 2022-04-25
Tos HIGH 8.1
CVE-2021-45841EPSS 8%

In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the us…

No fix yet
Fix from $1,950 2022-04-25
Tos HIGH 7.5
CVE-2021-45842

It is possible to obtain the first administrator's hash set up in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) on the system as well as o…

No fix yet
Fix from $1,950 2022-04-25
Tos MEDIUM 6.5
CVE-2021-45839EPSS 10%

It is possible to obtain the first administrator's hash set up on the system in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) as well as o…

No fix yet
Fix from $1,600 2022-04-25
F2 210 Firmware HIGH 7.3
CVE-2021-30127

TerraMaster F2-210 devices through 2021-04-03 use UPnP to make the admin web server accessible over the Internet on TCP port 8181, which is arguably …

Fix: after 2021-04-03
Fix from $1,950 2021-04-03
Tos CRITICAL 9.8
CVE-2020-15568EPSS 28%

TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerab…

Fix: 4.1.29+
Fix from $2,300 2021-01-30
Tos CRITICAL 9.8
CVE-2020-28187EPSS 16%

Multiple directory traversal vulnerabilities in TerraMaster TOS <= 4.2.06 allow remote authenticated attackers to read, edit or delete any file withi…

Fix: after 4.2.06
Fix from $2,300 2020-12-24
Tos CRITICAL 9.8
CVE-2020-28188EPSS 97%

Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/m…

Fix: after 4.2.06
Fix from $2,300 2020-12-24
Tos HIGH 8.1
CVE-2020-29189

Incorrect Access Control vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated attackers to bypass read-only restriction and obtain …

Fix: after 4.2.06
Fix from $1,950 2020-12-24
Tos HIGH 7.3
CVE-2020-28186

Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functionality and achieve account t…

Fix: after 4.2.06
Fix from $1,950 2020-12-24
Tos MEDIUM 5.9
CVE-2020-28190

TerraMaster TOS <= 4.2.06 was found to check for updates (of both system and applications) via an insecure channel (HTTP). Man-in-the-middle attacker…

Fix: after 4.2.06
Fix from $1,600 2020-12-24
Tos MEDIUM 5.4
CVE-2020-28184

Cross-site scripting (XSS) vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated users to inject arbitrary web script or HTML via th…

Fix: after 4.2.06
Fix from $1,600 2020-12-24
Tos MEDIUM 5.3
CVE-2020-28185EPSS 18%

User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system via the…

Fix: after 4.2.06
Fix from $1,600 2020-12-24
Terramaster Operating System CRITICAL 9.8
CVE-2020-35665EPSS 78%

An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in includ…

Fix: after 4.2.06
Fix from $2,300 2020-12-23
F2 210 Firmware HIGH 8.8
CVE-2019-18195

An issue was discovered on TerraMaster FS-210 4.0.19 devices. Normal users can use 1.user.php for privilege elevation.

No fix yet
Fix from $1,950 2019-10-28
Fs 210 Firmware HIGH 7.5
CVE-2019-18385

An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the include/makecvs.php?Event= s…

No fix yet
Fix from $1,950 2019-10-23
Fs 210 Firmware MEDIUM 6.5
CVE-2019-18384

An issue was discovered on TerraMaster FS-210 4.0.19 devices. An authenticated remote non-administrative user can read unauthorized shared files, as …

No fix yet
Fix from $1,600 2019-10-23
Fs 210 Firmware HIGH 7.5
CVE-2019-18383

An issue was discovered on TerraMaster FS-210 4.0.19 devices. One can download backup files remotely from terramaster_TNAS-00E43A_config_backup.bin w…

Mitigation only
Fix from $1,950 2019-10-23
Terramaster Operating System HIGH 8.8
CVE-2018-13359EPSS 20%

Cross-site scripting in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "modgroup" parameter.

No fix yet
Fix from $1,950 2018-11-27
Terramaster Operating System HIGH 8.8
CVE-2018-13418EPSS 5%

System command injection in ajaxdata.php in TerraMaster TOS 3.1.03 allows attackers to execute system commands via the "newname" parameter.

No fix yet
Fix from $1,950 2018-11-27
Terramaster Operating System MEDIUM 6.1
CVE-2018-13360

Cross-site scripting in Text Editor in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "filename" URL parameter.

No fix yet
Fix from $1,600 2018-11-27
Terramaster Operating System MEDIUM 5.3
CVE-2018-13361EPSS 17%

User enumeration in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to list all system users via the "modgroup" parameter.

No fix yet
Fix from $1,600 2018-11-27
Terramaster Operating System CRITICAL 9.8
CVE-2018-13336EPSS 9%

System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "pwd" parameter during…

No fix yet
Fix from $2,300 2018-11-27
Terramaster Operating System CRITICAL 9.8
CVE-2018-13338EPSS 10%

System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "username" parameter d…

No fix yet
Fix from $2,300 2018-11-27
Terramaster Operating System CRITICAL 9.8
CVE-2018-13350EPSS 17%

SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter.

No fix yet
Fix from $2,300 2018-11-27
Terramaster Operating System CRITICAL 9.8
CVE-2018-13354EPSS 23%

System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter.

No fix yet
Fix from $2,300 2018-11-27