vendor:
TOS
by:
Simone 'evilsocket' Margaritelli
9,8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: TOS
Affected Version From: TOS 3.0.30
Affected Version To: TOS 3.0.30
Patch Exists: YES
Related CWE: N/A
CPE: a:terramaster:tos
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017
Terramaster NAS Unauthenticated RCE as root
This exploit allows an attacker to execute arbitrary code on a vulnerable TerraMaster NAS device running TOS version 3.0.30 or earlier. The exploit works by uploading a malicious PHP script to the device, which is then executed remotely. The script is uploaded using a specially crafted HTTP request, which includes a cookie with the value 'kod_name' set to '1'. The script is then executed by sending an HTTP request to the URL of the uploaded script.
Mitigation:
Upgrade to the latest version of TOS, which is not vulnerable to this exploit.