References https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/webapp/TerraMaster-TOS-createRaid-%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E-CVE-2022-24989.md https://zhuanlan.zhihu.com/p/646400737 https://www.rapid7.com/db/modules/exploit/linux/http/terramaster_unauth_rce_cve_2022_24990/ https://nvd.nist.gov/vuln/detail/CVE-2022-24990 https://octagon.net/blog/2022/03/07/cve-2022-24990-terrmaster-tos-unauthenticated-remote-command-execution-via-php-object-instantiation/ https://github.com/0xf4n9x/CVE-2022-24990 https://www.sentinelone.com/vulnerability-database/cve-2020-28188/ https://nvd.nist.gov/vuln/detail/CVE-2020-28188 https://packetstormsecurity.com/files/172904/TerraMaster-TOS-4.2.29-Remote-Code-Execution.html https://forum.terra-master.com/en/viewtopic.php?f=28&t=3187
Related VulnerabilitiesPoCCVE-2020-29134: TOTVS Fluig <= 1.7.0 - Arbitrary File ReadPoCCVE-2023-54391: Proxmox VE - Default Credentials with TFA BypassPoCCVE-2026-0702: VidShop for WooCommerce <= 1.1.4 - SQL InjectionPoCCVE-2026-19092: Tutor LMS < 4.0.6 - Unauthenticated Arbitrary PHP Function InvocationPoCCVE-2026-27454: Discourse <=2026.2.0 - Hidden Post Revision Disclosure via revert_to Authorization BypassPoCCVE-2026-28141: NextGEN Gallery <= 4.2.3 - Reflected Cross-Site ScriptingPoCCVE-2026-28411: WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract()PoCCVE-2026-30849: MantisBT < 2.28.1 - SOAP API Authentication BypassPoCCVE-2026-34234: CtrlPanel <= 1.1.1 - Remote Code ExecutionPoCCVE-2026-41452: Krayin CRM < 2.2.1 - Installer Authentication BypassPoCCVE-2026-41456: Bludit CMS <= 3.20.0 - Cross-Site ScriptingPoCCVE-2026-41679: Paperclip - Remote Code ExecutionPoCCVE-2026-41948: Dify <=1.14.1 - Unauthenticated Plugin Daemon Path Traversal