Termix
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 19 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from October 1, 2025 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Termix: MFA-critical operations accept the account password as a sole factor (regression of CVE-2026-45749)
Termix: Authenticated SSRF via `/homepage/proxy` — No Destination Allowlist
Termix: Hardcoded default key encrypts all OIDC/WebAuthn users' stored SSH credentials — full offline decryption from a database copy
Termix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-controlled domain/email
Termix: Cross-User Information Disclosure via Missing Ownership Check in deploy-to-host Endpoint
Termix: Command injection in SSH key deployment verification
Termix: Authenticated users can read other users' host status and clear global SSH connections
Termix Vulnerable to Arbitrary Command Execution in File Manager
Termix's TOTP two-factor authentication can be disabled or bypassed using only the account password
Termix Vulnerable to Remote Code Execution via SSH Tunnel Forward Command Injection
Monitor Termix in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.