Description
Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally.
Published: 2026-07-17
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The TTSSH2 plugin in Tera Term has an improper handling of length parameters that can lead to out‑of‑bounds read and write during SSH negotiation with a server controlled by an attacker. When Tera Term attempts to establish a connection, portions of memory adjacent to the expected buffer may be exposed and sent to the malicious host, enabling the attacker to obtain sensitive data or cause the client to crash.

Affected Systems

Affected product is the TTSSH2 SSH client plugin of Tera Term, provided by the TeraTerm Project. No specific version information is supplied in the advisory; all releases of the plugin before the advisory are potentially vulnerable.

Risk and Exploitability

Risk: The CVSS score of 5.1 indicates a moderate severity primarily due to potential information disclosure and application instability. The EPSS metric shows an exploitation probability of less than 1%, and the vulnerability is not listed in CISA's KEV catalog, implying limited active exploitation. The most realistic attack scenario is remote: an attacker hosts a malicious SSH server and lures or coerces a user to connect with Tera Term. If the connection is established, the plugin’s out‑of‑bounds read/write could expose sensitive memory contents or cause an unexpected termination. No public exploits have been reported and the vulnerability requires the user to initiate contact with an attacker‑controlled server, so overall risk is moderate but not critical.

Generated by OpenCVE AI on August 1, 2026 at 08:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Tera Term release that contains the TTSSH2 patch from the official project site.
  • Block or monitor outbound SSH connections to untrusted hosts by configuring firewalls or proxy servers.
  • Educate users to verify SSH host keys and avoid connecting to unknown servers before initiating a session.

Generated by OpenCVE AI on August 1, 2026 at 08:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Handling in TTSSH2 Plugin May Lead to Information Disclosure

Tue, 28 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read/Write in TTSSH2 Plugin Causing Information Leakage

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Teraterm Project
Teraterm Project ttssh2
Vendors & Products Teraterm Project
Teraterm Project ttssh2

Wed, 22 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read/Write in TTSSH2 Plugin Causing Information Leakage

Fri, 17 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Description Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally.
Weaknesses CWE-130
References
Metrics cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Teraterm Project Ttssh2
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-07-17T13:09:30.703Z

Reserved: 2026-07-10T02:15:09.033Z

Link: CVE-2026-60060

cve-icon Vulnrichment

Updated: 2026-07-17T13:09:18.400Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T08:45:02Z

Weaknesses
  • CWE-130

    Improper Handling of Length Parameter Inconsistency