Termix 是一个基于 Web 的服务器管理平台,具备 SSH 终端、隧道转发和文件编辑等功能。在版本 1.8.0 至 2.5.1 之间,已认证的 Termix 用户可以在未经主机级授权的情况下访问服务器状态(server-stats)API。具体表现为: 会返回请求者无权访问的主机状态信息; 接受攻击者提供的数字格式主机标识符; 允许普通用户清除全局 SSH 连接池。 受影响的端点 暴露了主机的在线/离线状态及最近检测时间戳,可能导致其他用户的活跃会话或连接池被中断。虽然未认证的请求仍被阻止,但仅靠用户认证无法
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Termix-SSH | Termix | >= 1.8.0, < 2.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79766 | 9.1 CRITICAL | Termix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-c |
| CVE-2026-79764 | 7.7 HIGH | Termix: Authenticated SSRF via `/homepage/proxy` — No Destination Allowlist |
| CVE-2026-79761 | 6.6 MEDIUM | Termix: Command injection in SSH key deployment verification |
| CVE-2026-79760 | 6.4 MEDIUM | Termix: Authenticated blind SSRF through notification channel test endpoints |
| CVE-2026-79762 | 5.5 MEDIUM | Termix: Hardcoded default key encrypts all OIDC/WebAuthn users' stored SSH credentials — f |
| CVE-2026-79763 | 5.3 MEDIUM | Termix: MFA-critical operations accept the account password as a sole factor (regression o |
| CVE-2026-79759 | 4.3 MEDIUM | Termix: Cross-User Information Disclosure via Missing Ownership Check in deploy-to-host En |
No comments yet