← Vulnerability feed

Vulnerability record · CVE-2020-35665 · published 23 December 2020

CVE-2020-35665: TerraMaster TOS unauthenticated OS command injection in CSV creation

Terra Master · Terramaster Operating System

TerraMaster TOS through 4.2.06 passes the Event parameter in include/makecvs.php to a shell without sanitization during CSV creation, allowing OS command injection. Because the endpoint is reachable without authentication, any network attacker who can reach the device can execute commands as the web service user.

9.8 CVSS 3.1 Critical EPSS 78% · top 0.4% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution with a 9.8 CVSS score, public exploit code, and very high EPSS probability makes this an urgent patch-or-isolate case.

What it is

TerraMaster TOS through 4.2.06 passes the Event parameter in include/makecvs.php to a shell without sanitization during CSV creation, allowing OS command injection. Because the endpoint is reachable without authentication, any network attacker who can reach the device can execute commands as the web service user.

Impact

An attacker gains arbitrary command execution on the NAS with the privileges of the TOS web service, enabling data theft, persistence, or use of the device as a foothold into the network.

Attack surface

Reached over the network via HTTP requests to include/makecvs.php with crafted shell metacharacters in the Event parameter; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Not listed in CISA KEV, but public exploit code exists (Exploit-DB 49330, Packet Storm, pentest.com.tr) and EPSS is 0.7848 (99.56th percentile), indicating high likelihood of exploitation.

What to do

  • Upgrade TerraMaster TOS to a version later than 4.2.06; if no fixed release is available, isolate the device.
  • Block or restrict external and untrusted network access to the TOS web interface, especially include/makecvs.php.
  • Place the NAS behind a firewall or VPN and remove any direct internet exposure.
  • Audit the TOS web service account for unexpected files, processes, or scheduled tasks and rotate credentials.
  • Monitor vendor advisories for a confirmed patched version since the record does not name one.

Detection

  • Inspect web server logs for requests to include/makecvs.php containing shell metacharacters (;, |, $(), backticks) in the Event parameter.
  • Alert on unexpected child processes spawned by the TOS web service (for example shell, wget, curl, nc).
  • Monitor for outbound connections from the NAS to unfamiliar hosts that could indicate command-and-control or payload retrieval.
  • Review file integrity of TOS web files and watch for new scripts or cron entries created after suspicious requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-35665 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2022-24990TerraMaster NAS missing authentication exposes admin passwordTerraMaster NAS 4.2.29 and earlier fails to require authentication on module/api.php?mobile/webNasIPS, allowing a remote attacker who sends a 'User-A…KEVEPSS 83%analysed9.8CVE-2022-24989Terra-master terramaster operating system injection vulnerabilityTerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Objec…EPSS 32%9.8CVE-2018-13336Terra-master terramaster operating system os command injection vulnerabilitySystem command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "pwd" parameter during…EPSS 9.1%9.8CVE-2018-13338Terra-master terramaster operating system os command injection vulnerabilitySystem command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "username" parameter d…EPSS 10%9.8CVE-2018-13350Terra-master terramaster operating system sql injection vulnerabilitySQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter.EPSS 17%9.8CVE-2018-13354Terra-master terramaster operating system os command injection vulnerabilitySystem command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter.EPSS 23%9.8CVE-2017-9328Terra-master terramaster operating system os command injection vulnerabilityShell metacharacter injection vulnerability in /usr/www/include/ajax/GetTest.php in TerraMaster TOS before 3.0.34 leads to remote code execution as r…EPSS 7.4%8.8CVE-2018-13359Terra-master terramaster operating system cross-site scripting vulnerabilityCross-site scripting in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "modgroup" parameter.EPSS 20%

Source: NIST National Vulnerability Database (record CVE-2020-35665), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.