CVE-2020-35665
An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- December 23, 2020
- Published Date
- December 23, 2020
- Last Updated
- August 04, 2024
- Vendor
- n/a
- Product
- n/a
- Description
- An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation.
CVSS Scores
EPSS Score
- Score
- 89.37% (Percentile: 99.50%) as of 2025-04-29
Exploit Status
- Exploited in the Wild
- Yes (added 2025-04-27 00:00:00 UTC) Source
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
The Shadowserver (via CIRCL) | 2025-04-27 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/terramaster_unauth_rce_cve_2020_35665.rb | 2025-04-29 11:01:15 UTC |