CVE-2020-28185: TerraMaster Tos

Medium severity, CVSS 5.3. EPSS: 18.3% chance of exploitation in the next 30 days.

User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system via the username parameter to wizard/initialise.php.

Affected products

Published 2020-12-24. Last modified 2026-06-17.