CVE-2020-28185: TerraMaster Tos
Medium severity, CVSS 5.3. EPSS: 18.3% chance of exploitation in the next 30 days.
User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system via the username parameter to wizard/initialise.php.
Affected products
- TerraMaster Tos: up to and including 4.2.06
Published 2020-12-24. Last modified 2026-06-17.