9.8
CVSSv3

CVE-2020-35665

Published: 23/12/2020 Updated: 12/06/2023
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An unauthenticated command-execution vulnerability exists in TerraMaster TOS up to and including 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

terra-master terramaster operating system

Exploits

This Metasploit module exploits an unauthenticated remote code execution vulnerability in TerraMaster TOS versions 4206 and below via shell metacharacters in the Event parameter at vulnerable endpoint include/makecvsphp during CSV creation Any unauthenticated user can therefore execute commands on the system under the same privileges as the web ...