CVE-2020-35665

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
23/12/2020
Last modified:
12/06/2023

Description

An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:terra-master:terramaster_operating_system:*:*:*:*:*:*:*:* 4.2.06 (including)