Terramaster Operating System

Vendor:

First CVE: Sep 15, 2017 · Active for 8 years

28
Total CVEs
More Total CVEs than 97% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 63% of tracked products
3.6%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Terramaster Operating System over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 15, 2017
8 years ago
Most Recent CVE
Aug 20, 2023
1,073 days ago

CVE Severity & Scoring

Terramaster Operating System28 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network28 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None17 (60.7%)
Unknown0 (0.0%)
Required11 (39.3%)
Privileges Required
Low7 (25.0%)
High2 (7.1%)
None19 (67.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading
Feb 7, 20237.597YESYES
An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creati
Dec 23, 20209.886NOYES
TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?
Aug 20, 20239.858NOYES
System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter.
Nov 27, 20189.843NONO
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "checkName" parameter.
Nov 27, 20188.839NONO
SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter.
Nov 27, 20189.837NONO
Cross-site scripting in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "modgroup" parameter.
Nov 27, 20188.836NONO
Shell metacharacter injection vulnerability in /usr/www/include/ajax/GetTest.php in TerraMaster TOS before 3.0.34 leads to remote code execution as root.
Sep 15, 20179.834NONO
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "username" parameter during user creation.
Nov 27, 20189.833NONO
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "pwd" parameter during user creation.
Nov 27, 20189.832NONO

Exploit Exposure

Signals from CVEs in this product scope (28 CVEs).

CISA KEV
1 CVE
3.6% of CVEs· 98th percentile
Metasploit
3 CVEs
10.7% of CVEs· 97th percentile
Nuclei
1 CVE
3.6% of CVEs· 97th percentile
ExploitDB
1 CVE
3.6% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (28 CVEs).

Media Mentions

Signals from CVEs in this product scope (28 CVEs).

Top CNAs Publishing CVEs For Terramaster Operating System

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.1.03247.36.6%00