Multiple CVEs Discovered in Termix Server Management Platform

Multiple CVEs Discovered in Termix Server Management Platform

First seen 6 Jun 2026, 19:22 UTC CvefeedNvd.Nistcve.org 81% similarity 70.5

Article Content

Browse articles
ThreatCluster

Termix, a web-based server management platform, has been found vulnerable to remote code execution (RCE) attacks via two critical CVEs: CVE-2026-45748 and CVE-2026-45750. Both vulnerabilities exist in the platform's SSH functionalities, allowing attackers to inject malicious commands through improperly sanitized user inputs. CVE-2026-45748 affects the `POST /ssh/tunnel/connect` endpoint, while CVE-2026-45750 impacts the `GET /ssh/file_manager/ssh/resolvePath` endpoint. Both vulnerabilities were published on June 5, 2026, and are fixed in version 2.3.2 of Termix. The vulnerabilities could potentially allow unauthorized access to sensitive systems if exploited. Currently, no specific affected products have been listed, but the vulnerabilities pose a significant risk to users of the Termix platform.

Key Points: • Termix has critical RCE vulnerabilities identified as CVE-2026-45748 and CVE-2026-45750. • Both vulnerabilities stem from improper input handling in SSH-related functionalities. • Version 2.3.2 of Termix addresses these vulnerabilities; users are urged to update immediately.

ThreatCluster AI

Timeline

2026-06-05
CVE-2026-45748 published
CVE-2026-45748 disclosed, affecting Termix's SSH tunnel command processing, allowing OS command injection.
Cvefeed
2026-06-05
CVE-2026-45750 published
CVE-2026-45750 disclosed, impacting Termix's file manager path resolution, leading to shell command execution.
Nvd.Nist
2026-06-06
Patch released for Termix
Termix version 2.3.2 released to address both CVEs, users advised to update immediately.
Nvd.Nist

Community

Browse all →