Intrusion Prevention

TerraMaster.TOS.sysname.Parameter.XSS

Description

This indicates an attack attempt to exploit a Cross-Site Scripting Vulnerability in TerraMaster TOS.
The vulnerability is due to an input validation error when parsing a malicious HTTP request. A remote attacker may be able to inject an HTML element that allows them to evaluate arbitrary JavaScript within the user's browser in the device's origin.

Affected Products

TerraMaster TOS version 3.1.03

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Recommended Actions

Apply the most recent upgrade or patch from the vendor:
https://www.terra-master.com/global/tos/

CVE References

CVE-2018-13334