MASTER vendor intelligence

MASTER Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting MASTER products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse MASTER KEVs Full KEV feed
Total KEVs
9
Known exploited vulnerabilities affecting MASTER products
In CISA KEV
1
Records also listed in the official catalog
Beyond CISA KEV
8
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
MASTER KEVs with sensor-observed exploitation activity

The catalog gap matters for MASTER exposure

Eight of the nine exploited MASTER CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 89% of this vendor portfolio.

11%
Covered by CISA
89%
Beyond CISA
5
Product families

Attested MASTER CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2024-55457

MasterSAM Star Gate 11 is vulnerable to directory traversal via /adama/adama/downloadService. An attacker can exploit this vulnerability by...

Star Gate 11 High Beyond CISA 07 Jun 2026
CVE-2020-28185

User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system...

TOS High Beyond CISA 04 Jan 2026
CVE-2020-28188

Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via...

TOS High Beyond CISA 09 Jul 2025
CVE-2020-15568

TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation...

TOS High Beyond CISA 05 Jun 2025
CVE-2020-35949

An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to...

Quiz and Survey Master High Beyond CISA 13 Aug 2020
CVE-2020-35665

An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in...

TOS High Beyond CISA 27 Apr 2025
CVE-2022-24990

TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to...

NAS Confirmed In CISA 10 Feb 2023
CVE-2019-8387

MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component.

IPCAMERA01 High Beyond CISA 08 May 2019
CVE-2018-13350

SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter.

TOS High Beyond CISA 27 Nov 2018

Showing 9 of 9 MASTER known exploited vulnerabilities.

Recurring weakness patterns

Neutralization, limitation, and missing authentication for critical function account for four mapped occurrences across this MASTER KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.