PT-2020-16942 · Terramaster · Terramaster Tos

Published

2020-12-24

·

Updated

2020-12-28

·

CVE-2020-28187

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TerraMaster TOS versions 4.2.06 and earlier
Description The issue allows remote authenticated attackers to read, edit, or delete any file within the filesystem. This can be achieved via the filename parameter to "/tos/index.php?editor/fileGet", Event parameter to "/include/ajax/logtable.php", or opt parameter to "/include/core/index.php".
Recommendations For TerraMaster TOS versions 4.2.06 and earlier, as a temporary workaround, consider restricting access to the vulnerable API endpoints "/tos/index.php?editor/fileGet", "/include/ajax/logtable.php", and "/include/core/index.php" until a patch is available. Avoid using the filename, Event, and opt parameters in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-28187

Affected Products

Terramaster Tos