Cvefeed
Multiple CVEs Discovered in Termix Server Management Platform
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Termix, a web-based server management platform, has been found vulnerable to remote code execution (RCE) attacks via two critical CVEs: CVE-2026-45748 and CVE-2026-45750. Both vulnerabilities exist in the platform's SSH functionalities, allowing attackers to inject malicious commands through improperly sanitized user inputs. CVE-2026-45748 affects the `POST /ssh/tunnel/connect` endpoint, while CVE-2026-45750 impacts the `GET /ssh/file_manager/ssh/resolvePath` endpoint. Both vulnerabilities were published on June 5, 2026, and are fixed in version 2.3.2 of Termix. The vulnerabilities could potentially allow unauthorized access to sensitive systems if exploited. Currently, no specific affected products have been listed, but the vulnerabilities pose a significant risk to users of the Termix platform.
Key Points: • Termix has critical RCE vulnerabilities identified as CVE-2026-45748 and CVE-2026-45750. • Both vulnerabilities stem from improper input handling in SSH-related functionalities. • Version 2.3.2 of Termix addresses these vulnerabilities; users are urged to update immediately.