CVE-2026-45749
Termix 2.1.0 – 2.3.2
Raw vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NSummary
CVE-2026-45749 is a high-severity Use of Single-factor Authentication (CWE-308) vulnerability in Termix Termix. Its CVSS base score is 8.1 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Password Spraying (T1110.003); ranked at the 25th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
The strongest mitigations our analysis identified map to IA-2 (Identification and Authentication (Organizational Users)) and IA-8 (Identification and Authentication (Non-organizational Users)) — see the control section below for these in your framework.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-34877
Vulnerability Data
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /users/totp/disable` and `POST /users/totp/backup-codes` endpoints in Termix prior to version 2.3.2 accept the account password as a sole authentication factor for MFA-critical operations.…
more
An attacker who obtains a user's password (phishing, credential stuffing, the passwordHash leak in GHSA-xxxx) can disable TOTP entirely or regenerate backup codes, without ever possessing the TOTP device or knowing a valid TOTP code. This renders two-factor authentication ineffective. Version 2.3.2 patches the issue.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
—
V6.3.4V6.3.6V6.4.2V6.4.3
Mitigating Controls (NIST 800-53 r5) AI
ia-2 requires unique identification and authentication of users, directly stopping single-factor schemes by mandating appropriate (multi-factor) mechanisms.
ia-8 requires unique identification and authentication of non-organizational users, directly stopping single-factor schemes by mandating appropriate (multi-factor) mechanisms.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Explicit MFA requirement directly eliminates single-factor authentication while the control also addresses broader authentication scope.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Secure authentication control explicitly requires multi-factor authentication, directly eliminating single-factor weakness.
Authentication information control directly addresses the need for strong, multi-factor credentials.
Access control policy can mandate multi-factor authentication but does not prescribe the technical implementation.
Access rights provisioning can require MFA, yet the control is broader than authentication strength.
Privileged access rights can be conditioned on MFA, but the control focuses on privilege scope rather than factor count.
Information access restriction can enforce MFA, yet the control is wider than authentication mechanisms.