TerraMaster vendor intelligence

TerraMaster Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting TerraMaster products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Total KEVs
6
Known exploited vulnerabilities affecting TerraMaster products
In CISA KEV
1
Records also listed in the official catalog
Beyond CISA KEV
5
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
TerraMaster KEVs with sensor-observed exploitation activity

The catalog gap matters for TerraMaster exposure

Five of the six exploited TerraMaster CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 83% of this vendor portfolio.

17%
Covered by CISA
83%
Beyond CISA
2
Product families

Attested TerraMaster CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2020-28185

User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system...

TOS High Beyond CISA 04 Jan 2026
CVE-2020-28188

Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via...

TOS High Beyond CISA 09 Jul 2025
CVE-2020-15568

TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation...

TOS High Beyond CISA 05 Jun 2025
CVE-2020-35665

An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in...

TOS High Beyond CISA 27 Apr 2025
CVE-2022-24990

TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to...

NAS Confirmed In CISA 10 Feb 2023
CVE-2018-13350

SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter.

TOS High Beyond CISA 27 Nov 2018

Showing 6 of 6 TerraMaster known exploited vulnerabilities.

Recurring weakness patterns

Neutralization, missing authentication for critical function, and neutralization account for four mapped occurrences across this TerraMaster KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.