CVE-2026-45748: Termix Vulnerable to Remote Code Execution via SSH Tunnel Forward Command Injection
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The POST /ssh/tunnel/connect endpoint in Termix prior to version 2.3.2 builds an SSH tunnel command by interpolating user-controlled host record fields (endpointIP, endpointUsername, password) directly into a shell command without escaping, allowing persistent OS command injection on the source SSH host. Version 2.3.2 patches the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Termixto a version that resolves this vulnerability.Fixed in 2.3.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45748?
CVE-2026-45748 has a severity score of 9.8, categorizing it as critical.
How do I fix CVE-2026-45748?
To fix CVE-2026-45748, upgrade to Termix version 2.3.2 or a later version.
What type of vulnerability is CVE-2026-45748?
CVE-2026-45748 is classified as an OS Command Injection vulnerability.
What can attackers do with CVE-2026-45748?
Attackers can execute remote code via SSH tunnel forward command injection due to this vulnerability.
Is user interaction required for CVE-2026-45748 to be exploited?
No, CVE-2026-45748 does not require user interaction to be exploited.