CVE-2026-45787

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confidentiality and integrity failures for synced bookmark/profile data. Attackers can crack common passwords across installs and perform undetected ciphertext bit-flips to alter config/bookmarks. This vulnerability is fixed in 3.9.5.
Configurations

Configuration 1 (hide)

cpe:2.3:a:electerm_project:electerm:*:*:*:*:*:*:*:*

History

03 Jun 2026, 17:56

Type Values Removed Values Added
References () https://github.com/electerm/electerm/commit/9dd8295e37d53396b980cd45dfc5ed11ad79b937 - () https://github.com/electerm/electerm/commit/9dd8295e37d53396b980cd45dfc5ed11ad79b937 - Patch
References () https://github.com/electerm/electerm/security/advisories/GHSA-g29v-q6h7-76wh - () https://github.com/electerm/electerm/security/advisories/GHSA-g29v-q6h7-76wh - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
First Time Electerm Project
Electerm Project electerm
CPE cpe:2.3:a:electerm_project:electerm:*:*:*:*:*:*:*:*

28 May 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-28 18:16

Updated : 2026-06-03 17:56


NVD link : CVE-2026-45787

Mitre link : CVE-2026-45787

CVE.ORG link : CVE-2026-45787


JSON object : View

Products Affected

electerm_project

  • electerm
CWE
CWE-326

Inadequate Encryption Strength

CWE-329

Generation of Predictable IV with CBC Mode

CWE-353

Missing Support for Integrity Check

CWE-759

Use of a One-Way Hash without a Salt

CWE-916

Use of Password Hash With Insufficient Computational Effort