Impact
Termix’s GET /ssh/file_manager/ssh/resolvePath endpoint allows OS command injection by using double‑quote escaping that does not filter $(...) or backtick substitutions. This flaw lets an authenticated user with an active File Manager SSH session execute arbitrary shell commands on the remote host that Termix connects to. The result is uncontrolled code execution, making the attacker able to read, modify, or delete data, install software, or pivot to other systems.
Affected Systems
The vulnerability affects Termix versions prior to 2.3.2, the web‑based server management platform that provides SSH terminals, tunneling, and file editing. Versions 2.3.2 and later include the patch that eliminates the vulnerable endpoint.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity. EPSS is not available, so the current exploitation probability cannot be quantified, and the issue is not listed in CISA’s KEV catalog. Attackers need only an authenticated account with File Manager access to exploit the flaw, making the vector likely internal but requiring legitimate credentials. Given the high impact and confirmed exploitation path, the overall risk is severe.
OpenCVE Enrichment