Vulnerability record · CVE-2020-28188 · published 24 December 2020
CVE-2020-28188: TerraMaster TOS unauthenticated OS command injection in makecvs.php
Terra Master · Tos
TerraMaster TOS 4.2.06 and earlier passes the Event parameter of /include/makecvs.php into OS commands without sanitization, allowing command injection. Because the endpoint is reachable without authentication, any network attacker can run arbitrary commands on the device.
Description
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote command execution with a 9.8 CVSS score and very high EPSS probability, with public exploit references.
What it is
TerraMaster TOS 4.2.06 and earlier passes the Event parameter of /include/makecvs.php into OS commands without sanitization, allowing command injection. Because the endpoint is reachable without authentication, any network attacker can run arbitrary commands on the device.
Impact
An attacker gains remote code execution as the web service user, enabling full compromise of the NAS, including data theft, persistence and use in a botnet.
Attack surface
Reached over the network via HTTP requests to /include/makecvs.php with a crafted Event parameter; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV, but EPSS is 0.966 (99.9th percentile) and multiple references are tagged Exploit, including a Check Point report on botnet use, so public exploitation is well established.
What to do
- Upgrade TerraMaster TOS to a version later than 4.2.06; if no fixed release is available, isolate the device from untrusted networks.
- Block or restrict external access to /include/makecvs.php and the TOS web interface at the firewall or reverse proxy.
- Place NAS management interfaces on a separate VLAN or management network, not exposed to the internet.
- Monitor vendor advisories for a patched TOS release and apply it as soon as it is published.
Detection
- Inspect web server logs for requests to /include/makecvs.php, especially with shell metacharacters in the Event parameter.
- Alert on outbound connections from the NAS to unexpected hosts, which may indicate botnet or reverse-shell activity.
- Monitor for unexpected child processes spawned by the web server (for example shell or curl/wget) on the device.
- Review TOS audit or system logs for command execution or file changes outside normal administrative activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/172880/TerraMaster-TOS-4.2.06-Remote-Code-Execution.html | |
| https://research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilities-for-creating-a-botnet/ | ExploitThird Party Advisory |
| https://www.ihteam.net/advisory/terramaster-tos-multiple-vulnerabilities/ | ExploitThird Party Advisory |
| https://www.terra-master.com/ | Vendor Advisory |
| http://packetstormsecurity.com/files/172880/TerraMaster-TOS-4.2.06-Remote-Code-Execution.html | |
| https://research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilities-for-creating-a-botnet/ | ExploitThird Party Advisory |
| https://www.ihteam.net/advisory/terramaster-tos-multiple-vulnerabilities/ | ExploitThird Party Advisory |
| https://www.terra-master.com/ | Vendor Advisory |
Track CVE-2020-28188 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-28188), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.