CVE-2026-60060

Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally.

Scoring

Severity
MEDIUM
CVSS base score
6.3
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
EPSS probability
0.32%
CWE
CWE-130
Published
2026-07-17
Last modified
2026-07-17

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs