← Vulnerability feed

Vulnerability record · CVE-2020-28188 · published 24 December 2020

CVE-2020-28188: TerraMaster TOS unauthenticated OS command injection in makecvs.php

Terra Master · Tos

TerraMaster TOS 4.2.06 and earlier passes the Event parameter of /include/makecvs.php into OS commands without sanitization, allowing command injection. Because the endpoint is reachable without authentication, any network attacker can run arbitrary commands on the device.

9.8 CVSS 3.1 Critical EPSS 97% · top 0.1% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
97%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution with a 9.8 CVSS score and very high EPSS probability, with public exploit references.

What it is

TerraMaster TOS 4.2.06 and earlier passes the Event parameter of /include/makecvs.php into OS commands without sanitization, allowing command injection. Because the endpoint is reachable without authentication, any network attacker can run arbitrary commands on the device.

Impact

An attacker gains remote code execution as the web service user, enabling full compromise of the NAS, including data theft, persistence and use in a botnet.

Attack surface

Reached over the network via HTTP requests to /include/makecvs.php with a crafted Event parameter; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Not listed in CISA KEV, but EPSS is 0.966 (99.9th percentile) and multiple references are tagged Exploit, including a Check Point report on botnet use, so public exploitation is well established.

What to do

  • Upgrade TerraMaster TOS to a version later than 4.2.06; if no fixed release is available, isolate the device from untrusted networks.
  • Block or restrict external access to /include/makecvs.php and the TOS web interface at the firewall or reverse proxy.
  • Place NAS management interfaces on a separate VLAN or management network, not exposed to the internet.
  • Monitor vendor advisories for a patched TOS release and apply it as soon as it is published.

Detection

  • Inspect web server logs for requests to /include/makecvs.php, especially with shell metacharacters in the Event parameter.
  • Alert on outbound connections from the NAS to unexpected hosts, which may indicate botnet or reverse-shell activity.
  • Monitor for unexpected child processes spawned by the web server (for example shell or curl/wget) on the device.
  • Review TOS audit or system logs for command execution or file changes outside normal administrative activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-28188 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-45837Terra-master tos vulnerabilityIt is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically crafted in…EPSS 16%9.8CVE-2021-45840Terra-master tos vulnerabilityIt is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending specifically crafted inpu…EPSS 3.9%9.8CVE-2020-15568Terra-master tos improper control of dynamically-managed code vulnerabilityTerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerab…EPSS 29%9.8CVE-2020-28187Terra-master tos path traversal vulnerabilityMultiple directory traversal vulnerabilities in TerraMaster TOS <= 4.2.06 allow remote authenticated attackers to read, edit or delete any file withi…EPSS 16%8.8CVE-2021-45836Terra-master tos vulnerabilityAn authenticated attacker can execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by injecting a malicious…EPSS 2.5%8.1CVE-2021-45841Terra-master tos improper authentication vulnerabilityIn Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the us…EPSS 8.4%8.1CVE-2020-29189Terra-master tos vulnerabilityIncorrect Access Control vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated attackers to bypass read-only restriction and obtain …EPSS 1.9%7.5CVE-2021-45842Terra-master tos vulnerabilityIt is possible to obtain the first administrator's hash set up in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) on the system as well as o…EPSS 2.4%

Source: NIST National Vulnerability Database (record CVE-2020-28188), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.