Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Termix-SSH — Vulnerabilities & Security Advisories 25

Browse all 25 CVE security advisories affecting Termix-SSH. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates vulnerability data for the vendor Termix-SSH, specifically focusing on their SSH-based products and associated security weaknesses. It collects records of identified flaws, including authentication bypass, remote code execution, and protocol-level issues, covering the historical time range of publicly disclosed security advisories. Readers can use this hub to track the vendor's published security notices, analyze specific weakness classes, and review the complete vulnerability history for Termix-SSH products.

Top products by Termix-SSH: Termix
CVE ID Title CVSS Severity Published
CVE-2026-79763 Termix: MFA-critical operations accept the account password as a sole factor (regression of CVE-2026-45749) — Termix CWE-308 5.3 Medium 2026-09-24
CVE-2026-79764 Termix: Authenticated SSRF via `/homepage/proxy` — No Destination Allowlist — Termix CWE-918 7.7 High 2026-09-24
CVE-2026-79762 Termix: Hardcoded default key encrypts all OIDC/WebAuthn users' stored SSH credentials — full offline decryption from a database copy — Termix CWE-321 5.5 Medium 2026-09-24
CVE-2026-79766 Termix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-controlled domain/email — Termix CWE-78 9.1 Critical 2026-09-24
CVE-2026-79759 Termix: Cross-User Information Disclosure via Missing Ownership Check in deploy-to-host Endpoint — Termix CWE-639 4.3 Medium 2026-09-24
CVE-2026-79761 Termix: Command injection in SSH key deployment verification — Termix CWE-78 6.6 Medium 2026-09-24
CVE-2026-79758 Termix: Authenticated users can read other users' host status and clear global SSH connections — Termix CWE-284 5.4 Medium 2026-09-24
CVE-2026-79760 Termix: Authenticated blind SSRF through notification channel test endpoints — Termix CWE-918 6.4 Medium 2026-09-24
CVE-2026-53545 Termix: Remote Code Execution via Tunnel Disconnect pkill Command Injection — Termix CWE-78 9.8 Critical 2026-08-19
CVE-2026-53546 Termix: Missing authorization in SSH host credential resolution exposes stored credentials — Termix CWE-639 9.6 Critical 2026-08-19
CVE-2026-53542 Termix: Tar option injection in file-manager archive creation allows command execution on managed SSH hosts — Termix CWE-78 8.8 High 2026-08-19
CVE-2026-53548 Termix: IDOR — Authenticated user can fetch SSH passwords for hosts owned by other users — Termix CWE-285 9.6 Critical 2026-08-19
CVE-2026-53547 Termix: Account Takeover via Global Settings Disclosure — Termix CWE-862 8.8 High 2026-08-19
CVE-2026-53549 Termix: Server-Side Request Forgery via Proxy Connectivity Test — Termix CWE-918 7.7 High 2026-08-19
CVE-2026-45750 Termix Vulnerable to Arbitrary Command Execution in File Manager — Termix CWE-78 9.0 Critical 2026-06-05
CVE-2026-45749 Termix's TOTP two-factor authentication can be disabled or bypassed using only the account password — Termix CWE-308 8.1 High 2026-06-05
CVE-2026-45748 Termix Vulnerable to Remote Code Execution via SSH Tunnel Forward Command Injection — Termix CWE-78 9.8 Critical 2026-06-05
CVE-2026-45746 Termix Vulnerable to Arbitrary Command Execution via Session Hijacking — Termix CWE-284 9.0 Critical 2026-06-05
CVE-2026-45744 Termix has an OS Command Injection in File Manager resolvePath endpoint — Termix CWE-78 9.9 Critical 2026-06-05
CVE-2026-45743 Termix has a File-Manager Session Hijack via Missing Ownership Check (IDOR) — Termix CWE-639 8.1 High 2026-06-05
CVE-2026-45745 Termix has improper certificate validation in Electron desktop client that enables MITM credential/token theft — Termix CWE-295 8.0 High 2026-06-05
CVE-2026-42454 Termix: OS Command Injection in Docker Container Management Endpoints — Termix CWE-78 9.9 Critical 2026-05-08
CVE-2026-42453 Termix: Command injection in extractArchive/compressFiles via double-quote escaping bypass — Termix CWE-77 9.8AI Critical AI 2026-05-08
CVE-2026-42452 Termix: Pending-TOTP temporary token can regenerate backup codes and neutralize TOTP — Termix CWE-304 8.1 High 2026-05-08
CVE-2026-22804 Termix has a Stored XSS in File Manager leading to Local File Inclusion (LFI) in Electron and Session Hijacking in Browser — Termix CWE-269 8.0 High 2026-01-12

This page lists every published CVE security advisory associated with Termix-SSH. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.