Termix 是一个基于 Web 的服务器管理平台,提供 SSH 终端、隧道转发和文件编辑等功能。在版本 2.5.0 至 2.5.1 中, 端点接受已认证用户的 查询参数,并将其直接传递给 或 ,且未对目标地址进行任何限制。在 文件中, 仅执行语法层面的验证,允许请求访问回环地址(loopback)、RFC1918 私有地址、链路本地地址以及云元数据服务地址。该端点会返回完整获取的 JSON 响应,因此,低权限用户或自行注册的用户可以借此泄露内部服务数据和云凭证。此问题已在版本 2.5.1 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Termix-SSH | Termix | >= 2.5.0, < 2.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79766 | 9.1 CRITICAL | Termix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-c |
| CVE-2026-79761 | 6.6 MEDIUM | Termix: Command injection in SSH key deployment verification |
| CVE-2026-79760 | 6.4 MEDIUM | Termix: Authenticated blind SSRF through notification channel test endpoints |
| CVE-2026-79762 | 5.5 MEDIUM | Termix: Hardcoded default key encrypts all OIDC/WebAuthn users' stored SSH credentials — f |
| CVE-2026-79758 | 5.4 MEDIUM | Termix: Authenticated users can read other users' host status and clear global SSH connect |
| CVE-2026-79763 | 5.3 MEDIUM | Termix: MFA-critical operations accept the account password as a sole factor (regression o |
| CVE-2026-79759 | 4.3 MEDIUM | Termix: Cross-User Information Disclosure via Missing Ownership Check in deploy-to-host En |
No comments yet