CyberRota Analysis
AI-GeneratedThe Termix web-based server management platform is vulnerable due to its /homepage/proxy endpoint, which allows authenticated users to make unrestricted HTTP requests, potentially exposing internal service data and cloud credentials. This flaw can be exploited by low-privilege or self-registered accounts, leading to significant data exfiltration risks. Organizations using versions 2.5.0 to 2.5.1 should prioritize upgrading to version 2.5.1 to mitigate this high-severity vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0 until 2.5.1, the /homepage/proxy endpoint accepts an authenticated user's url query parameter and passes it to http.get or https.get without destination restrictions. In src/backend/database/routes/homepage-proxy-routes.ts, new URL performs only syntactic validation, allowing requests to loopback, RFC1918, link-local, and cloud metadata destinations. The endpoint returns the complete fetched JSON response, so a low-privilege or self-registered account can exfiltrate internal service data and cloud credentials. This issue is fixed in version 2.5.1.