CVE-2020-28190: TerraMaster Tos
Medium severity, CVSS 5.9. EPSS: 0.8% chance of exploitation in the next 30 days.
TerraMaster TOS <= 4.2.06 was found to check for updates (of both system and applications) via an insecure channel (HTTP). Man-in-the-middle attackers are able to intercept these requests and serve a weaponized/infected version of applications or updates.
Affected products
- TerraMaster Tos: up to and including 4.2.06
Published 2020-12-24. Last modified 2026-06-17.