CVE-2020-28186: TerraMaster Tos

High severity, CVSS 7.3. EPSS: 4.1% chance of exploitation in the next 30 days.

Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functionality and achieve account takeover.

Affected products

Published 2020-12-24. Last modified 2026-06-17.