TerraMaster TOS <= 4.2.06 is susceptible to a remote code execution vulnerability which could allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php via the Event parameter.
id: CVE-2020-28188
info:
name: TerraMaster TOS - Unauthenticated Remote Command Execution
autho
...