Termix 是一款基于 Web 的服务器管理平台,提供 SSH 终端、隧道功能和文件编辑能力。在版本 1.7.0 至 2.5.1 中,Termix 的 SSH 密钥部署流程从用户可控的公钥令牌中提取一个 grep 模式,并将其插值到在选定目标主机上执行的双引号 shell 命令中。在 文件中,两种 验证路径均允许在 中接受命令替换或破坏引号的 shell 语法。因此,已认证且能够部署精心构造的 SSH 凭据的用户,就可以以所选远程账户的权限执行命令。独立的 ACME 命令注入报告不在本 CVE 的范围之内。此问题
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Termix-SSH | Termix | >= 1.7.0, < 2.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79766 | 9.1 CRITICAL | Termix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-c |
| CVE-2026-79764 | 7.7 HIGH | Termix: Authenticated SSRF via `/homepage/proxy` — No Destination Allowlist |
| CVE-2026-79760 | 6.4 MEDIUM | Termix: Authenticated blind SSRF through notification channel test endpoints |
| CVE-2026-79762 | 5.5 MEDIUM | Termix: Hardcoded default key encrypts all OIDC/WebAuthn users' stored SSH credentials — f |
| CVE-2026-79758 | 5.4 MEDIUM | Termix: Authenticated users can read other users' host status and clear global SSH connect |
| CVE-2026-79763 | 5.3 MEDIUM | Termix: MFA-critical operations accept the account password as a sole factor (regression o |
| CVE-2026-79759 | 4.3 MEDIUM | Termix: Cross-User Information Disclosure via Missing Ownership Check in deploy-to-host En |
No comments yet