CVE-2020-28188
CVE-2020-28188
Vexday Risk Score
40Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS —EPSS 96.6%KEV nãoPoC —Nuclei simMetasploit simPatch —
Lifecycle
12 Dec 2020Metasploit module available
24 Dec 2020Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://packetstormsecurity.com/files/172880/TerraMaster-TOS-4.2.06-Remote-Code-Execution.htmlhttps://research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilities-for-creating-a-botnet/https://www.ihteam.net/advisory/terramaster-tos-multiple-vulnerabilities/https://www.terra-master.com/