CVE-2020-28186: TerraMaster Tos
High severity, CVSS 7.3. EPSS: 4.1% chance of exploitation in the next 30 days.
Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functionality and achieve account takeover.
Affected products
- TerraMaster Tos: up to and including 4.2.06
Published 2020-12-24. Last modified 2026-06-17.