Vulnerability index

Browse CVEs

46 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2022-24989EPSS 32% TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Objec… Terramaster Operating System 4.2.31+ Fix from $2,3002023-08-20 HIGH 7.5 CVE-2022-24990 KEVEPSS 83% TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mo… Terramaster Operating System 4.2.31+ Fix from $1,9502023-02-07 CRITICAL 9.8 CVE-2021-45837EPSS 16% It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically crafted in… Tos No fix yet Fix from $2,3002022-04-25 CRITICAL 9.8 CVE-2021-45840 It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending specifically crafted inpu… Tos No fix yet Fix from $2,3002022-04-25 HIGH 8.8 CVE-2021-45836 An authenticated attacker can execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by injecting a malicious… Tos No fix yet Fix from $1,9502022-04-25 HIGH 8.1 CVE-2021-45841EPSS 8% In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the us… Tos No fix yet Fix from $1,9502022-04-25 HIGH 7.5 CVE-2021-45842 It is possible to obtain the first administrator's hash set up in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) on the system as well as o… Tos No fix yet Fix from $1,9502022-04-25 MEDIUM 6.5 CVE-2021-45839EPSS 10% It is possible to obtain the first administrator's hash set up on the system in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) as well as o… Tos No fix yet Fix from $1,6002022-04-25 HIGH 7.3 CVE-2021-30127 TerraMaster F2-210 devices through 2021-04-03 use UPnP to make the admin web server accessible over the Internet on TCP port 8181, which is arguably … F2 210 Firmware after 2021-04-03 Fix from $1,9502021-04-03 CRITICAL 9.8 CVE-2020-15568EPSS 28% TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerab… Tos 4.1.29+ Fix from $2,3002021-01-30 CRITICAL 9.8 CVE-2020-28187EPSS 16% Multiple directory traversal vulnerabilities in TerraMaster TOS <= 4.2.06 allow remote authenticated attackers to read, edit or delete any file withi… Tos after 4.2.06 Fix from $2,3002020-12-24 CRITICAL 9.8 CVE-2020-28188EPSS 97% Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/m… Tos after 4.2.06 Fix from $2,3002020-12-24 HIGH 8.1 CVE-2020-29189 Incorrect Access Control vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated attackers to bypass read-only restriction and obtain … Tos after 4.2.06 Fix from $1,9502020-12-24 HIGH 7.3 CVE-2020-28186 Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functionality and achieve account t… Tos after 4.2.06 Fix from $1,9502020-12-24 MEDIUM 5.9 CVE-2020-28190 TerraMaster TOS <= 4.2.06 was found to check for updates (of both system and applications) via an insecure channel (HTTP). Man-in-the-middle attacker… Tos after 4.2.06 Fix from $1,6002020-12-24 MEDIUM 5.4 CVE-2020-28184 Cross-site scripting (XSS) vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated users to inject arbitrary web script or HTML via th… Tos after 4.2.06 Fix from $1,6002020-12-24 MEDIUM 5.3 CVE-2020-28185EPSS 18% User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system via the… Tos after 4.2.06 Fix from $1,6002020-12-24 CRITICAL 9.8 CVE-2020-35665EPSS 78% An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in includ… Terramaster Operating System after 4.2.06 Fix from $2,3002020-12-23 HIGH 8.8 CVE-2019-18195 An issue was discovered on TerraMaster FS-210 4.0.19 devices. Normal users can use 1.user.php for privilege elevation. F2 210 Firmware No fix yet Fix from $1,9502019-10-28 HIGH 7.5 CVE-2019-18385 An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the include/makecvs.php?Event= s… Fs 210 Firmware No fix yet Fix from $1,9502019-10-23 MEDIUM 6.5 CVE-2019-18384 An issue was discovered on TerraMaster FS-210 4.0.19 devices. An authenticated remote non-administrative user can read unauthorized shared files, as … Fs 210 Firmware No fix yet Fix from $1,6002019-10-23 HIGH 7.5 CVE-2019-18383 An issue was discovered on TerraMaster FS-210 4.0.19 devices. One can download backup files remotely from terramaster_TNAS-00E43A_config_backup.bin w… Fs 210 Firmware Mitigation only Fix from $1,9502019-10-23 HIGH 8.8 CVE-2018-13359EPSS 20% Cross-site scripting in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "modgroup" parameter. Terramaster Operating System No fix yet Fix from $1,9502018-11-27 HIGH 8.8 CVE-2018-13418EPSS 5% System command injection in ajaxdata.php in TerraMaster TOS 3.1.03 allows attackers to execute system commands via the "newname" parameter. Terramaster Operating System No fix yet Fix from $1,9502018-11-27 MEDIUM 6.1 CVE-2018-13360 Cross-site scripting in Text Editor in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "filename" URL parameter. Terramaster Operating System No fix yet Fix from $1,6002018-11-27 MEDIUM 5.3 CVE-2018-13361EPSS 17% User enumeration in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to list all system users via the "modgroup" parameter. Terramaster Operating System No fix yet Fix from $1,6002018-11-27 CRITICAL 9.8 CVE-2018-13336EPSS 9% System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "pwd" parameter during… Terramaster Operating System No fix yet Fix from $2,3002018-11-27 CRITICAL 9.8 CVE-2018-13338EPSS 10% System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "username" parameter d… Terramaster Operating System No fix yet Fix from $2,3002018-11-27 CRITICAL 9.8 CVE-2018-13350EPSS 17% SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter. Terramaster Operating System No fix yet Fix from $2,3002018-11-27 CRITICAL 9.8 CVE-2018-13354EPSS 23% System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter. Terramaster Operating System No fix yet Fix from $2,3002018-11-27