Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
terra-master vulnerabilities and exploits
(subscribe to this query)
8.1
CVSSv3
CVE-2021-45841
In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the user's password hash. Guest users (disabled by default) can be abused using a null/empty hash and allow an unauthenticated ...
Terra-master Tos 4.2.15-2107141517
1 Metasploit module
7.5
CVSSv3
CVE-2019-18383
An issue exists on TerraMaster FS-210 4.0.19 devices. One can download backup files remotely from terramaster_TNAS-00E43A_config_backup.bin without permission.
Terra-master Fs-210 Firmware 4.0.19
6.5
CVSSv3
CVE-2019-18384
An issue exists on TerraMaster FS-210 4.0.19 devices. An authenticated remote non-administrative user can read unauthorized shared files, as demonstrated by the filename=*public*%25252Fadmin_OnlyRead.txt substring.
Terra-master Fs-210 Firmware 4.0.19
7.5
CVSSv3
CVE-2019-18385
An issue exists on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the include/makecvs.php?Event= substring.
Terra-master Fs-210 Firmware 4.0.19
7.2
CVSSv3
CVE-2018-13330
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows malicious users to execute system commands during group creation via the "groupname" parameter.
Terra-master Terramaster Operating System 3.1.03
6.1
CVSSv3
CVE-2018-13333
Cross-site scripting in File Manager in TerraMaster TOS version 3.1.03 allows malicious users to execute JavaScript in the permissions window by placing JavaScript in users' usernames.
Terra-master Terramaster Operating System 3.1.03
5.4
CVSSv3
CVE-2018-13335
Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows malicious users to execute JavaScript when viewing shared folders via their descriptions.
Terra-master Terramaster Operating System 3.1.03
5.4
CVSSv3
CVE-2018-13337
Session Fixation in the web application for TerraMaster TOS version 3.1.03 allows malicious users to control users' session cookies via JavaScript.
Terra-master Terramaster Operating System 3.1.03
6.1
CVSSv3
CVE-2018-13329
Cross-site scripting in ajaxdata.php in TerraMaster TOS version 3.1.03 allows malicious users to execute JavaScript via the "lines" URL parameter.
Terra-master Terramaster Operating System 3.1.03
6.1
CVSSv3
CVE-2018-13331
Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows malicious users to execute JavaScript when viewing users by placing JavaScript in their usernames.
Terra-master Terramaster Operating System 3.1.03
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
denial of service
CVE-2024-27371
CVE-2024-20405
CVE-2024-31627
CVE-2024-31625
race condition
CVE-2024-4358
cross-site scripting
CVE-2023-20938
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »