Termix 是一个基于 Web 的服务器管理平台,具备 SSH 终端、隧道功能和文件编辑功能。在版本 2.4.1 至 2.5.1 之间,已认证的 Termix 管理员可通过调用 接口存储由攻击者控制的域名和电子邮件值,并通过调用 接口触发这些值被插值到 certbot 的 shell 命令中。在 文件中, 以 执行这些值时,仅用双引号进行包裹,因此攻击者可以利用 shell 元字符执行任意操作系统命令,从而以 Termix 后端进程的身份实现远程代码执行。HTTP 验证和 DNS Cloudflare 验证两种挑
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Termix-SSH | Termix | >= 2.4.1, < 2.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79764 | 7.7 HIGH | Termix: Authenticated SSRF via `/homepage/proxy` — No Destination Allowlist |
| CVE-2026-79761 | 6.6 MEDIUM | Termix: Command injection in SSH key deployment verification |
| CVE-2026-79760 | 6.4 MEDIUM | Termix: Authenticated blind SSRF through notification channel test endpoints |
| CVE-2026-79762 | 5.5 MEDIUM | Termix: Hardcoded default key encrypts all OIDC/WebAuthn users' stored SSH credentials — f |
| CVE-2026-79758 | 5.4 MEDIUM | Termix: Authenticated users can read other users' host status and clear global SSH connect |
| CVE-2026-79763 | 5.3 MEDIUM | Termix: MFA-critical operations accept the account password as a sole factor (regression o |
| CVE-2026-79759 | 4.3 MEDIUM | Termix: Cross-User Information Disclosure via Missing Ownership Check in deploy-to-host En |
No comments yet