Tos
Vendor:
First CVE: Dec 24, 2020 · Active for 5 years
14
Total CVEs
More Total CVEs than 92% of tracked products
4.7
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 72% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Tos over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 24, 2020
5 years ago
Most Recent CVE
Apr 25, 2022
1,555 days ago
CVE Severity & Scoring
Tos14 CVEs
29%
36%
36%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (85.7%)
High2 (14.3%)
Unknown0 (0.0%)
User Interaction
None13 (92.9%)
Unknown0 (0.0%)
Required1 (7.1%)
Privileges Required
Low4 (28.6%)
High0 (0.0%)
None10 (71.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-28188CRITICAL Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter. | Dec 24, 2020 | 9.8 | 91 | NO | YES |
CVE-2020-15568CRITICAL TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php | Jan 30, 2021 | 9.8 | 57 | NO | YES |
CVE-2021-45837CRITICAL It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically crafted input to /tos/index.php?app/del. | Apr 25, 2022 | 9.8 | 42 | NO | YES |
CVE-2021-45841HIGH In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the user's password hash. Guest users | Apr 25, 2022 | 8.1 | 40 | NO | YES |
CVE-2021-45839MEDIUM It is possible to obtain the first administrator's hash set up on the system in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) as well as other information such as MAC ad | Apr 25, 2022 | 6.5 | 36 | NO | YES |
CVE-2020-28187CRITICAL Multiple directory traversal vulnerabilities in TerraMaster TOS <= 4.2.06 allow remote authenticated attackers to read, edit or delete any file within the filesystem via the (1) fi | Dec 24, 2020 | 9.8 | 35 | NO | NO |
CVE-2020-28185MEDIUM User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system via the username parameter to wizard/i | Dec 24, 2020 | 5.3 | 35 | NO | YES |
CVE-2021-45840CRITICAL It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending specifically crafted input to /tos/index.php?app/app_sta | Apr 25, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-45836HIGH An authenticated attacker can execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by injecting a maliciously crafted input in the request | Apr 25, 2022 | 8.8 | 28 | NO | NO |
CVE-2020-29189HIGH Incorrect Access Control vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated attackers to bypass read-only restriction and obtain full access to any folder withi | Dec 24, 2020 | 8.1 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
28.6% of CVEs· 98th percentile
Nuclei
3 CVEs
21.4% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Tos
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.2.15-2107141517 | 6 | 8.4 | 7.1% | 0 | 3 |