SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-58317

MEDIUM · CVSS 6.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The TTSSH2 plugin of Tera Term is vulnerable to an unsigned to signed conversion error, which can lead to out-of-bounds read/write operations during SSH connections to malicious servers. This vulnerability may result in the unintended transmission of adjacent memory contents, potentially exposing sensitive information and causing abnormal behavior or crashes in Tera Term. Organizations using Tera Term for SSH connections should prioritize addressing this issue to mitigate potential data leaks and service disruptions.

CVE
CVE-2026-58317
Severity
MEDIUM
CVSS
6.3
EPSS
0.18%

Original NVD Description

Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally.