KEVIntel
9.8
CVSS
Critical

CVE-2020-15568

PUBLISHED

TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation...

PoC available Remote Low complexity No user interaction
Vendor
TerraMaster
Product
TOS
Published
Jan 30, 2021
EPSS
93.1% · 100% pctl

Description

TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter.

php nuclei_scanner

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 10.0

AV:N/AC:L/Au:N/C:C/I:C/A:C

Exploitation status

Proof of concept available

Recorded 2023-02-21 13:10:45 UTC · Source

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
The Shadowserver (via CIRCL) Jun 05, 2025

Scanner integrations

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

divinepwner/TerraMaster-TOS-CVE-2020-15568

github · Created 2023-02-21 13:10:45 UTC · 3 stars

Repository for CVE-2020-15568 Metasploit module

n0bugz/CVE-2020-15568

github · Created 2022-10-22 17:20:01 UTC · 2 stars

A quick and easy POC for CVE-2020-15568

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Proof of Concept Exploit Available

  • Detected by Nuclei

  • Added to KEVIntel