{"id":"CVE-2020-28188","aliases":[],"url":"https://o3.security/vulnerability/CVE-2020-28188","summary":"Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.","details":"Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.","published":"2020-12-24T00:00:00.000Z","modified":"2024-08-04T16:33:58.217Z","cvss":null,"epss":{"score":0.96598,"percentile":0.99878,"asOf":"2026-08-25"},"cisaKev":null,"exploitsKnown":4,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.terra-master.com/"},{"type":"WEB","url":"https://www.ihteam.net/advisory/terramaster-tos-multiple-vulnerabilities/"},{"type":"WEB","url":"https://research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilities-for-creating-a-botnet/"},{"type":"WEB","url":"http://packetstormsecurity.com/files/172880/TerraMaster-TOS-4.2.06-Remote-Code-Execution.html"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2024-08-04T16:33:58.217Z"}}