CVE-2020-28188
62Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 97%
from disclosure to weapon0 days
Published on NVDDec 24
metasploitDec 12
VulnCheck+26d
exploitation probability
97%top 1% of all CVEs
observed exploitation
yesVulnCheck
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.
Affected products
n/a · n/aReferences
http://packetstormsecurity.com/files/172880/TerraMaster-TOS-4.2.06-Remote-Code-Execution.htmlhttps://research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilities-for-creating-a-botnet/https://www.ihteam.net/advisory/terramaster-tos-multiple-vulnerabilities/https://www.terra-master.com/