Vulnerabilities (CVE)

Filtered by vendor Terra-master Subscribe
Filtered by product Tos
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-45839 1 Terra-master 3 F2-210, F4-210, Tos 2022-05-05 4.0 MEDIUM 6.5 MEDIUM
It is possible to obtain the first administrator's hash set up on the system in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) as well as other information such as MAC address, internal IP address etc. by performing a request to the /module/api.php?mobile/webNasIPS endpoint.
CVE-2020-28190 1 Terra-master 1 Tos 2020-12-28 4.3 MEDIUM 5.9 MEDIUM
TerraMaster TOS <= 4.2.06 was found to check for updates (of both system and applications) via an insecure channel (HTTP). Man-in-the-middle attackers are able to intercept these requests and serve a weaponized/infected version of applications or updates.
CVE-2020-28185 1 Terra-master 1 Tos 2020-12-28 5.0 MEDIUM 5.3 MEDIUM
User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system via the username parameter to wizard/initialise.php.
CVE-2020-28184 1 Terra-master 1 Tos 2020-12-28 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated users to inject arbitrary web script or HTML via the mod parameter to /module/index.php.