First published: Thu Dec 24 2020(Updated: )
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TerraMaster TOS | <=4.2.06 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28188 is rated as a high-severity vulnerability due to its potential for remote command execution.
To fix CVE-2020-28188, upgrade TerraMaster TOS to a version higher than 4.2.06.
CVE-2020-28188 affects all versions of TerraMaster TOS up to and including 4.2.06.
Yes, CVE-2020-28188 can be exploited by remote unauthenticated attackers.
CVE-2020-28188 is a Remote Command Execution (RCE) vulnerability.