Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 08 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Jun 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:termix:termix:*:*:*:*:*:*:*:* |
Sun, 07 Jun 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Termix
Termix termix |
|
| Vendors & Products |
Termix
Termix termix |
Fri, 05 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/file_manager/ssh/resolvePath endpoint in the Termix File Manager component unsafely processes the path parameter and embeds it into a shell command executed over the active SSH session. Because the user-controlled value is placed inside double quotes and only double quotes are escaped, shell command substitution syntax such as $(...) is still interpreted by the remote shell. Version 2.3.2 fixes the issue. | |
| Title | Termix Vulnerable to Arbitrary Command Execution in File Manager | |
| Weaknesses | CWE-639 CWE-78 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-10T03:58:36.556Z
Reserved: 2026-05-13T06:54:34.221Z
Link: CVE-2026-45750
Updated: 2026-06-08T16:09:32.356Z
Status : Modified
Published: 2026-06-05T18:17:32.463
Modified: 2026-06-08T17:16:44.830
Link: CVE-2026-45750
No data.
OpenCVE Enrichment
Updated: 2026-06-07T11:00:11Z