Authorization Flaw in Next Terminal Allows Unauthorized Asset Manipulation
CVE-2026-75108

5.3MEDIUM

Key Information:

Vendor
CVE Published:
17 August 2026

What is CVE-2026-75108?

The Next Terminal software has a critical vulnerability where it fails to apply necessary per-asset authorization checks on its portal ping and wake-on-LAN endpoints. This oversight allows any authenticated user to interact with assets they should not have access to. By exploiting this vulnerability, attackers can invoke these endpoints using arbitrary asset identifiers, thus obtaining sensitive asset information like display names, reachability status, connection timing, and network addresses. Furthermore, malicious actors can initiate wake-on-LAN requests on unauthorized assets, potentially leading to further exploitation.

Affected Version(s)

next-terminal 0 <= 3.3.7-b1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

geo-chen
.