CVE-2026-45787

Published: Mag 28, 2026 Last Modified: Mag 28, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,0
Attack Vector: network
Attack Complexity: high
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confidentiality and integrity failures for synced bookmark/profile data. Attackers can crack common passwords across installs and perform undetected ciphertext bit-flips to alter config/bookmarks. This vulnerability is fixed in 3.9.5.

326

Inadequate Encryption Strength

Draft
Common Consequences
Security Scopes Affected:
Access Control Confidentiality
Potential Impacts:
Bypass Protection Mechanism Read Application Data
Applicable Platforms
All platforms may be affected
View CWE Details
329

Generation of Predictable IV with CBC Mode

Draft
Common Consequences
Security Scopes Affected:
Confidentiality
Potential Impacts:
Read Application Data
Applicable Platforms
Technologies: ICS/OT
View CWE Details
353

Missing Support for Integrity Check

Draft
Common Consequences
Security Scopes Affected:
Integrity Other Non-Repudiation
Potential Impacts:
Other Hide Activities
Applicable Platforms
All platforms may be affected
View CWE Details
759

Use of a One-Way Hash without a Salt

Incomplete
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
View CWE Details
916

Use of Password Hash With Insufficient Computational Effort

Incomplete
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/electerm/electerm/commit/9dd8295e37d53396b980cd45dfc5ed11ad7…
https://github.com/electerm/electerm/security/advisories/GHSA-g29v-q6h7-76wh