Skip to main content
Mallory
CriticalPublic exploit

OS Command Injection in Termix /ssh/tunnel/connect

IdentifiersCVE-2026-45748CWE-78· Improper Neutralization of Special…

CVE-2026-45748 is an OS command injection vulnerability in Termix, a web-based server management platform that provides SSH terminal, tunneling, and file editing functionality. In Termix versions prior to 2.3.2, the POST /ssh/tunnel/connect endpoint constructs an SSH tunnel command by directly interpolating user-controlled host record fields, specifically endpointIP, endpointUsername, and password, into a shell command without proper escaping or neutralization of shell metacharacters. Because these values are incorporated into a command executed on the source SSH host, an attacker can inject arbitrary operating system commands. The issue is described as persistent because the malicious payload can be stored in host record fields and later triggered when the tunnel connection workflow is invoked.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows arbitrary OS command execution on the source SSH host in the security context used by the vulnerable Termix process or invoked command path. This can result in full compromise of confidentiality, integrity, and availability on the affected host, including execution of attacker-supplied commands, theft of credentials or sensitive configuration data, modification of files or system state, installation of persistence mechanisms, pivoting through SSH infrastructure, and disruption of service. The provided CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H indicates critical remote impact with high effects across confidentiality, integrity, and availability.

Mitigation

If you can’t patch tonight, do this now.

If immediate upgrade is not possible, restrict access to the Termix application and especially functionality that can create or modify host records or invoke POST /ssh/tunnel/connect. Remove or sanitize existing host records containing shell metacharacters or unexpected values in endpointIP, endpointUsername, and password. Limit network exposure of the Termix interface, enforce strong authentication and least-privilege access, and run the Termix service with minimal OS privileges to reduce post-exploitation impact. Monitor for suspicious tunnel invocations and unexpected command execution on source SSH hosts.

Remediation

Patch, then assume compromise.

Upgrade Termix to version 2.3.2 or later, which patches the vulnerable command construction in the POST /ssh/tunnel/connect endpoint. The fix should eliminate shell-based interpolation of untrusted host record fields and ensure that SSH tunnel parameters are passed safely without invoking a shell or with strict escaping and argument separation. Validate that all deployments are running the patched release and review stored host records for malicious values that may have been persisted prior to upgrade.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity5

Community discussion across Reddit, Mastodon, and other social sources.