Termix 是一个基于 Web 的服务器管理平台,具备 SSH 终端、隧道传输和文件编辑等功能。在版本 1.7.0 至 2.5.1 中,Termix 从提交的默认字符串以及 中公开的 userId 盐值派生出用于包装 OIDC 和 WebAuthn 用户的 Data Encryption Key(DEK)的密钥。由于 OIDC_SYSTEM_SECRET 和 WEBAUTHN_SYSTEM_SECRET 未在项目默认部署工件中配置,拥有离线 SQLite 数据库副本的攻击者可以推导出生成这些密钥所需的包装密钥,从
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Termix-SSH | Termix | >= 1.7.0, < 2.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79766 | 9.1 CRITICAL | Termix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-c |
| CVE-2026-79764 | 7.7 HIGH | Termix: Authenticated SSRF via `/homepage/proxy` — No Destination Allowlist |
| CVE-2026-79761 | 6.6 MEDIUM | Termix: Command injection in SSH key deployment verification |
| CVE-2026-79760 | 6.4 MEDIUM | Termix: Authenticated blind SSRF through notification channel test endpoints |
| CVE-2026-79758 | 5.4 MEDIUM | Termix: Authenticated users can read other users' host status and clear global SSH connect |
| CVE-2026-79763 | 5.3 MEDIUM | Termix: MFA-critical operations accept the account password as a sole factor (regression o |
| CVE-2026-79759 | 4.3 MEDIUM | Termix: Cross-User Information Disclosure via Missing Ownership Check in deploy-to-host En |
No comments yet