Termix 是一款基于 Web 的服务器管理平台,具备 SSH 终端、隧道传输和文件编辑等功能。在 2.5.0 至 2.5.1 版本中,Termix 允许经过身份验证的用户配置 webhook 或 ntfy 通知通道,并使用攻击者控制的目的地 URL,进而通过通知通道测试端点触发服务器端请求。 中的请求路径直接调用 ,未对目标地址进行白名单校验或阻止访问私有地址。这导致可以向 Termix 服务器可访问的内部 HTTP 服务发起盲请求。在 webhook 模式下,攻击者还可控制 HTTP 方法和请求头,若内部服务
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Termix-SSH | Termix | >= 2.5.0, < 2.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79766 | 9.1 CRITICAL | Termix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-c |
| CVE-2026-79764 | 7.7 HIGH | Termix: Authenticated SSRF via `/homepage/proxy` — No Destination Allowlist |
| CVE-2026-79761 | 6.6 MEDIUM | Termix: Command injection in SSH key deployment verification |
| CVE-2026-79762 | 5.5 MEDIUM | Termix: Hardcoded default key encrypts all OIDC/WebAuthn users' stored SSH credentials — f |
| CVE-2026-79758 | 5.4 MEDIUM | Termix: Authenticated users can read other users' host status and clear global SSH connect |
| CVE-2026-79763 | 5.3 MEDIUM | Termix: MFA-critical operations accept the account password as a sole factor (regression o |
| CVE-2026-79759 | 4.3 MEDIUM | Termix: Cross-User Information Disclosure via Missing Ownership Check in deploy-to-host En |
No comments yet