CVE-2024-34539: TerraMaster Tos

Critical severity, CVSS 9.4. EPSS: 0.5% chance of exploitation in the next 30 days.

Hardcoded credentials in TerraMaster TOS firmware through 5.1 allow a remote attacker to successfully login to the mail or webmail server. These credentials can also be used to login to the administration panel and to perform privileged actions.

Affected products

Published 2024-06-14. Last modified 2026-06-17.