MASTER Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for MASTER products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

9

In CISA KEV

1

Beyond CISA KEV

8

Sensor Observed

0

Virtual Patch Available

0

MASTER KEVs Added by Year

Loading...

9 MASTER KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2024-55457

MasterSAM Star Gate 11 is vulnerable to directory traversal via /adama/adama/downloadService. An attacker can exploit this vulnerability by...

High Not in CISA 07 Jun 2026
CVE-2020-28185

User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system...

High Not in CISA 04 Jan 2026
CVE-2020-28188

Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via...

High Not in CISA 09 Jul 2025
CVE-2020-15568

TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation...

High Not in CISA 05 Jun 2025
CVE-2020-35949

An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to...

High Not in CISA 13 Aug 2020
CVE-2020-35665

An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in...

High Not in CISA 27 Apr 2025
CVE-2022-24990

TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to...

Confirmed In CISA 10 Feb 2023
CVE-2019-8387

MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component.

High Not in CISA 08 May 2019
CVE-2018-13350

SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter.

High Not in CISA 27 Nov 2018

Common Vulnerability Classes (CWE)

  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 2
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
  • CWE-306 — Missing Authentication for Critical Function 1
  • CWE-434 — Unrestricted Upload of File with Dangerous Type 1
  • CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1
  • CWE-913 — Improper Control of Dynamically-Managed Code Resources 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology