Termix 是一个基于 Web 的服务器管理平台,具备 SSH 终端、隧道连接和文件编辑功能。在 2.4.0 至 2.5.1 版本中, 和 这两个 API 端点允许仅通过账户密码作为唯一的重新认证因素。这一漏洞源于 2.4.0 版本的一次重构,该重构回归(regressed)了为修复 CVE-2026-45749 而引入的双因素认证检查机制。 在源代码文件 中,函数 在 bcrypt 密码比对成功时即返回认证成功;而每个相关端点则允许将“密码”或“TOTP 验证码”作为可互换的认证凭据。这意味着,攻击者若已获取受
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Termix-SSH | Termix | >= 2.4.0, < 2.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79766 | 9.1 CRITICAL | Termix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-c |
| CVE-2026-79764 | 7.7 HIGH | Termix: Authenticated SSRF via `/homepage/proxy` — No Destination Allowlist |
| CVE-2026-79761 | 6.6 MEDIUM | Termix: Command injection in SSH key deployment verification |
| CVE-2026-79760 | 6.4 MEDIUM | Termix: Authenticated blind SSRF through notification channel test endpoints |
| CVE-2026-79762 | 5.5 MEDIUM | Termix: Hardcoded default key encrypts all OIDC/WebAuthn users' stored SSH credentials — f |
| CVE-2026-79758 | 5.4 MEDIUM | Termix: Authenticated users can read other users' host status and clear global SSH connect |
| CVE-2026-79759 | 4.3 MEDIUM | Termix: Cross-User Information Disclosure via Missing Ownership Check in deploy-to-host En |
No comments yet