TerraMaster Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for TerraMaster products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

6

In CISA KEV

1

Beyond CISA KEV

5

Sensor Observed

0

Virtual Patch Available

0

TerraMaster KEVs Added by Year

Loading...

6 TerraMaster KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2020-28185

User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system...

High Not in CISA 04 Jan 2026
CVE-2020-28188

Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via...

High Not in CISA 09 Jul 2025
CVE-2020-15568

TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation...

High Not in CISA 05 Jun 2025
CVE-2020-35665

An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in...

High Not in CISA 27 Apr 2025
CVE-2022-24990

TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to...

Confirmed In CISA 10 Feb 2023
CVE-2018-13350

SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter.

High Not in CISA 27 Nov 2018

Common Vulnerability Classes (CWE)

  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 2
  • CWE-306 — Missing Authentication for Critical Function 1
  • CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1
  • CWE-913 — Improper Control of Dynamically-Managed Code Resources 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology