CVE-2026-45787

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confidentiality and integrity failures for synced bookmark/profile data. Attackers can crack common passwords across installs and perform undetected ciphertext bit-flips to alter config/bookmarks. This vulnerability is fixed in 3.9.5.

Scoring

Severity
MEDIUM
CVSS base score
6
CVSS vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS probability
0.10%
CWE
CWE-326, CWE-329, CWE-353, CWE-759, CWE-916
Published
2026-05-28
Last modified
2026-05-29

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs