Terramaster Operating System
Vendor:
First CVE: Sep 15, 2017 · Active for 8 years
28
Total CVEs
More Total CVEs than 97% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 63% of tracked products
3.6%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Terramaster Operating System over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 15, 2017
8 years ago
Most Recent CVE
Aug 20, 2023
1,073 days ago
CVE Severity & Scoring
Terramaster Operating System28 CVEs
43%
32%
25%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network28 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None17 (60.7%)
Unknown0 (0.0%)
Required11 (39.3%)
Privileges Required
Low7 (25.0%)
High2 (7.1%)
None19 (67.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24990HIGH TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading | Feb 7, 2023 | 7.5 | 97 | YES | YES |
CVE-2020-35665CRITICAL An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creati | Dec 23, 2020 | 9.8 | 86 | NO | YES |
CVE-2022-24989CRITICAL TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php? | Aug 20, 2023 | 9.8 | 58 | NO | YES |
CVE-2018-13354CRITICAL System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter. | Nov 27, 2018 | 9.8 | 43 | NO | NO |
CVE-2018-13358HIGH System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "checkName" parameter. | Nov 27, 2018 | 8.8 | 39 | NO | NO |
CVE-2018-13350CRITICAL SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter. | Nov 27, 2018 | 9.8 | 37 | NO | NO |
CVE-2018-13359HIGH Cross-site scripting in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "modgroup" parameter. | Nov 27, 2018 | 8.8 | 36 | NO | NO |
CVE-2017-9328CRITICAL Shell metacharacter injection vulnerability in /usr/www/include/ajax/GetTest.php in TerraMaster TOS before 3.0.34 leads to remote code execution as root. | Sep 15, 2017 | 9.8 | 34 | NO | NO |
CVE-2018-13338CRITICAL System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "username" parameter during user creation. | Nov 27, 2018 | 9.8 | 33 | NO | NO |
CVE-2018-13336CRITICAL System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "pwd" parameter during user creation. | Nov 27, 2018 | 9.8 | 32 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (28 CVEs).
CISA KEV
1 CVE
3.6% of CVEs· 98th percentile
Metasploit
3 CVEs
10.7% of CVEs· 97th percentile
Nuclei
1 CVE
3.6% of CVEs· 97th percentile
ExploitDB
1 CVE
3.6% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (28 CVEs).
Media Mentions
Signals from CVEs in this product scope (28 CVEs).
Top CNAs Publishing CVEs For Terramaster Operating System
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.1.03 | 24 | 7.3 | 6.6% | 0 | 0 |