CVE-2020-28188
CVE-2020-28188
Vexday Risk Score
40Atención
Decisión SSVC (CISA)
Attend
PoC disponible → seguir de cerca
CVSS —EPSS 96.6%KEV nãoPoC —Nuclei simMetasploit simPatch —
Ciclo de vida
12 dic 2020Exploit Metasploit disponible
24 dic 2020Publicada en NVD
Recomendación: Planificar corrección próxima — ya existe PoC pública.
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://packetstormsecurity.com/files/172880/TerraMaster-TOS-4.2.06-Remote-Code-Execution.htmlhttps://research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilities-for-creating-a-botnet/https://www.ihteam.net/advisory/terramaster-tos-multiple-vulnerabilities/https://www.terra-master.com/