TerraMaster.TOS.ajaxdata.System.Command.Injection
Description
This indicates an attack attempt to exploit a Remote Code Execution Vulnerability in TerraMaster TOS.
The vulnerability is due to an input validation error when parsing a malicious HTTP request. A remote attacker may be able to exploit this to execute arbitrary code within the context of the application, via a crafted HTTP request.
Affected Products
TerraMaster TOS version 3.1.03
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor:
https://www.terra-master.com/global/tos/
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2020-05-27 | 15.852 | Sig Added |
2020-05-20 | 15.847 | Default_action:pass:drop |
2020-05-19 | 15.846 | Name:TerraMaster. TOS. User. Creation. System. Command. Injection:TerraMaster. TOS. ajaxdata. System. Command. Injection |
2020-05-12 | 15.842 |