Vulnerability record · CVE-2020-35665 · published 23 December 2020
CVE-2020-35665: TerraMaster TOS unauthenticated OS command injection in CSV creation
Terra Master · Terramaster Operating System
TerraMaster TOS through 4.2.06 passes the Event parameter in include/makecvs.php to a shell without sanitization during CSV creation, allowing OS command injection. Because the endpoint is reachable without authentication, any network attacker who can reach the device can execute commands as the web service user.
Description
An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote command execution with a 9.8 CVSS score, public exploit code, and very high EPSS probability makes this an urgent patch-or-isolate case.
What it is
TerraMaster TOS through 4.2.06 passes the Event parameter in include/makecvs.php to a shell without sanitization during CSV creation, allowing OS command injection. Because the endpoint is reachable without authentication, any network attacker who can reach the device can execute commands as the web service user.
Impact
An attacker gains arbitrary command execution on the NAS with the privileges of the TOS web service, enabling data theft, persistence, or use of the device as a foothold into the network.
Attack surface
Reached over the network via HTTP requests to include/makecvs.php with crafted shell metacharacters in the Event parameter; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV, but public exploit code exists (Exploit-DB 49330, Packet Storm, pentest.com.tr) and EPSS is 0.7848 (99.56th percentile), indicating high likelihood of exploitation.
What to do
- Upgrade TerraMaster TOS to a version later than 4.2.06; if no fixed release is available, isolate the device.
- Block or restrict external and untrusted network access to the TOS web interface, especially include/makecvs.php.
- Place the NAS behind a firewall or VPN and remove any direct internet exposure.
- Audit the TOS web service account for unexpected files, processes, or scheduled tasks and rotate credentials.
- Monitor vendor advisories for a confirmed patched version since the record does not name one.
Detection
- Inspect web server logs for requests to include/makecvs.php containing shell metacharacters (;, |, $(), backticks) in the Event parameter.
- Alert on unexpected child processes spawned by the TOS web service (for example shell, wget, curl, nc).
- Monitor for outbound connections from the NAS to unfamiliar hosts that could indicate command-and-control or payload retrieval.
- Review file integrity of TOS web files and watch for new scripts or cron entries created after suspicious requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/172880/TerraMaster-TOS-4.2.06-Remote-Code-Execution.html | |
| https://www.exploit-db.com/exploits/49330 | ExploitThird Party AdvisoryVDB Entry |
| https://www.pentest.com.tr/exploits/TerraMaster-TOS-4-2-06-Unauthenticated-Remote-Code-Execution.html | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/172880/TerraMaster-TOS-4.2.06-Remote-Code-Execution.html | |
| https://www.exploit-db.com/exploits/49330 | ExploitThird Party AdvisoryVDB Entry |
| https://www.pentest.com.tr/exploits/TerraMaster-TOS-4-2-06-Unauthenticated-Remote-Code-Execution.html | ExploitThird Party Advisory |
Track CVE-2020-35665 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-35665), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.