References https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/webapp/TerraMaster-TOS-createRaid-%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E-CVE-2022-24989.md https://zhuanlan.zhihu.com/p/646400737 https://www.rapid7.com/db/modules/exploit/linux/http/terramaster_unauth_rce_cve_2022_24990/ https://nvd.nist.gov/vuln/detail/CVE-2022-24990 https://octagon.net/blog/2022/03/07/cve-2022-24990-terrmaster-tos-unauthenticated-remote-command-execution-via-php-object-instantiation/ https://github.com/0xf4n9x/CVE-2022-24990 https://www.sentinelone.com/vulnerability-database/cve-2020-28188/ https://nvd.nist.gov/vuln/detail/CVE-2020-28188 https://packetstormsecurity.com/files/172904/TerraMaster-TOS-4.2.29-Remote-Code-Execution.html https://forum.terra-master.com/en/viewtopic.php?f=28&t=3187
Related VulnerabilitiesPoCCVE-2026-0692: BlueSnap Payment Gateway for WooCommerce <=3.4.0 - IPN Authorization BypassPoCCVE-2026-26216: Crawl4AI < 0.8.0 - Unauthenticated Remote Code Execution via Hooks ParameterPoCCVE-2026-40281: Gotenberg <= 8.30.1 - Remote Code ExecutionPoCCVE-2026-49468: LiteLLM Proxy < 1.84.0 - Host Header Authentication BypassPoCCVE-2026-86242: Bifrost < 1.6.3 - Unauthenticated Remote Plugin URL FetchPoCCVE-2024-57728: SimpleHelp <= 5.5.7 - Arbitrary File UploadPoCCVE-2025-11452: Asgaros Forum < 3.2.0 - SQL InjectionPoCCVE-2025-34033: Blue Angel Software Suite (5V Technologies) - OS Command InjectionPoCCVE-2026-12227: Visual Composer <= 45.16.0 - Unauthenticated LFIPoCCVE-2026-56681: 9router <=0.5.4 - Authentication BypassPoCCVE-2026-89013: Dolibarr < 24.0.0 - Authorization Bypass via hashp ParameterPoCCVE-2026-49060: Hippoo Mobile App for WooCommerce - Broken Access ControlPoCCVE-2026-58467: Cockpit CMS <= 2.14.0 - Path Traversal / Local File Inclusion