Vulnerability index

Browse CVEs

33 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Tos CRITICAL 9.8
CVE-2021-45837EPSS 16%

It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically crafted in…

No fix yet
Fix from $2,300 2022-04-25
Tos CRITICAL 9.8
CVE-2021-45840

It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending specifically crafted inpu…

No fix yet
Fix from $2,300 2022-04-25
Tos HIGH 8.8
CVE-2021-45836

An authenticated attacker can execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by injecting a malicious…

No fix yet
Fix from $1,950 2022-04-25
Tos HIGH 8.1
CVE-2021-45841EPSS 8%

In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the us…

No fix yet
Fix from $1,950 2022-04-25
Tos HIGH 7.5
CVE-2021-45842

It is possible to obtain the first administrator's hash set up in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) on the system as well as o…

No fix yet
Fix from $1,950 2022-04-25
Tos MEDIUM 6.5
CVE-2021-45839EPSS 10%

It is possible to obtain the first administrator's hash set up on the system in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) as well as o…

No fix yet
Fix from $1,600 2022-04-25
F2 210 Firmware HIGH 8.8
CVE-2019-18195

An issue was discovered on TerraMaster FS-210 4.0.19 devices. Normal users can use 1.user.php for privilege elevation.

No fix yet
Fix from $1,950 2019-10-28
Fs 210 Firmware HIGH 7.5
CVE-2019-18385

An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the include/makecvs.php?Event= s…

No fix yet
Fix from $1,950 2019-10-23
Fs 210 Firmware MEDIUM 6.5
CVE-2019-18384

An issue was discovered on TerraMaster FS-210 4.0.19 devices. An authenticated remote non-administrative user can read unauthorized shared files, as …

No fix yet
Fix from $1,600 2019-10-23
Fs 210 Firmware HIGH 7.5
CVE-2019-18383

An issue was discovered on TerraMaster FS-210 4.0.19 devices. One can download backup files remotely from terramaster_TNAS-00E43A_config_backup.bin w…

Mitigation only
Fix from $1,950 2019-10-23
Terramaster Operating System HIGH 8.8
CVE-2018-13359EPSS 20%

Cross-site scripting in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "modgroup" parameter.

No fix yet
Fix from $1,950 2018-11-27
Terramaster Operating System HIGH 8.8
CVE-2018-13418EPSS 5%

System command injection in ajaxdata.php in TerraMaster TOS 3.1.03 allows attackers to execute system commands via the "newname" parameter.

No fix yet
Fix from $1,950 2018-11-27
Terramaster Operating System MEDIUM 6.1
CVE-2018-13360

Cross-site scripting in Text Editor in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "filename" URL parameter.

No fix yet
Fix from $1,600 2018-11-27
Terramaster Operating System MEDIUM 5.3
CVE-2018-13361EPSS 17%

User enumeration in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to list all system users via the "modgroup" parameter.

No fix yet
Fix from $1,600 2018-11-27
Terramaster Operating System CRITICAL 9.8
CVE-2018-13336EPSS 9%

System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "pwd" parameter during…

No fix yet
Fix from $2,300 2018-11-27
Terramaster Operating System CRITICAL 9.8
CVE-2018-13338EPSS 10%

System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "username" parameter d…

No fix yet
Fix from $2,300 2018-11-27
Terramaster Operating System CRITICAL 9.8
CVE-2018-13350EPSS 17%

SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter.

No fix yet
Fix from $2,300 2018-11-27
Terramaster Operating System CRITICAL 9.8
CVE-2018-13354EPSS 23%

System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter.

No fix yet
Fix from $2,300 2018-11-27
Terramaster Operating System HIGH 8.8
CVE-2018-13353EPSS 6%

System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute commands via the "checkport" parameter.

No fix yet
Fix from $1,950 2018-11-27
Terramaster Operating System HIGH 8.8
CVE-2018-13356

Incorrect access control on ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to elevate user permissions.

No fix yet
Fix from $1,950 2018-11-27
Terramaster Operating System HIGH 8.8
CVE-2018-13358EPSS 25%

System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "checkName" parameter.

No fix yet
Fix from $1,950 2018-11-27
Terramaster Operating System HIGH 7.5
CVE-2018-13332

Directory Traversal in the explorer application in TerraMaster TOS version 3.1.03 allows attackers to upload files to arbitrary locations via the "pa…

No fix yet
Fix from $1,950 2018-11-27
Terramaster Operating System HIGH 7.5
CVE-2018-13352

Session Exposure in the web application for TerraMaster TOS version 3.1.03 allows attackers to view active session tokens in a world-readable directo…

No fix yet
Fix from $1,950 2018-11-27
Terramaster Operating System HIGH 7.2
CVE-2018-13330EPSS 8%

System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands during group creation via the …

No fix yet
Fix from $1,950 2018-11-27
Terramaster Operating System MEDIUM 6.5
CVE-2018-13355

Incorrect access controls in ajaxdata.php in TerraMaster TOS version 3.1.03 allow attackers to create user groups without proper authorization.

No fix yet
Fix from $1,600 2018-11-27
Terramaster Operating System MEDIUM 6.1
CVE-2018-13331

Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when viewing users by placing JavaScri…

No fix yet
Fix from $1,600 2018-11-27
Terramaster Operating System MEDIUM 6.1
CVE-2018-13333

Cross-site scripting in File Manager in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript in the permissions window by placing Ja…

No fix yet
Fix from $1,600 2018-11-27
Terramaster Operating System MEDIUM 6.1
CVE-2018-13349

Cross-site scripting in the web application taskbar in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the user's username.

No fix yet
Fix from $1,600 2018-11-27
Terramaster Operating System MEDIUM 5.4
CVE-2018-13335

Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when viewing shared folders via their …

No fix yet
Fix from $1,600 2018-11-27
Terramaster Operating System MEDIUM 5.4
CVE-2018-13357

Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when viewing Shared Folders via JavaSc…

No fix yet
Fix from $1,600 2018-11-27