Vulnerability CVE-2021-45836


Published: 2022-04-25

Description:
An authenticated attacker can execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by injecting a maliciously crafted input in the request through /tos/index.php?app/hand_app.

 References:
https://thatsn0tmy.site/posts/2021/12/how-to-summon-rces/

Copyright 2026, cxsecurity.com

 

Back to Top