Summary
CVE-2026-45748 is a critical unauthenticated OS command injection vulnerability (CWE-78) in Termix, a self-hosted, web-based server management platform providing SSH terminal access, SSH tunneling, and file editing capabilities. The flaw allows a remote, unauthenticated attacker to inject and execute arbitrary OS commands on the Termix server host by sending a crafted request to the POST /ssh/tunnel/connect API endpoint, achieving full persistent remote code execution (RCE). The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and is fixed in Termix version 2.3.2.
Technical details
- Root cause: The
POST /ssh/tunnel/connectendpoint constructs an SSH tunnel command via direct string interpolation of user-controlled host record fields —endpointIP,endpointUsername, andpassword— into a shell command without any escaping or sanitization. Special shell metacharacters in these fields are passed to the underlying shell as-is, enabling command injection (e.g., supplying127.0.0.1$(id>/tmp/pwn)as the endpoint IP executes the injected command on the SSH source host). - Trigger conditions: Sending a crafted
POST /ssh/tunnel/connectrequest with a malicious payload in any of the three interpolated fields (endpointIP,endpointUsername,password). No authentication is required. Auto-start tunnel configurations will persistently re-execute injected payloads on each process restart. - Attack vector: Fully remote, over the network (HTTP), requiring no credentials and no user interaction.
- Impact: Complete compromise of the Termix host — full confidentiality, integrity, and availability impact (C:H/I:H/A:H). Because Termix acts as a central hub for managing remote servers and storing SSH credentials, a successful exploit also exposes all managed hosts and stored credentials within the platform.
Affected software
- Termix (vendor: Termix-SSH) — all versions prior to 2.3.2
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate action: Upgrade Termix to version 2.3.2 or later, which patches the OS command injection by eliminating unsafe shell string interpolation of user-supplied host record fields.
- If immediate patching is not feasible: Restrict network access to the Termix web interface (default port 8080) to trusted networks only, and place the instance behind a firewall or VPN to prevent unauthenticated internet-facing exposure until an upgrade can be performed.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

