Authorization Flaw in Next Terminal Allows Unauthorized Asset Manipulation
CVE-2026-75108
5.3MEDIUM
What is CVE-2026-75108?
The Next Terminal software has a critical vulnerability where it fails to apply necessary per-asset authorization checks on its portal ping and wake-on-LAN endpoints. This oversight allows any authenticated user to interact with assets they should not have access to. By exploiting this vulnerability, attackers can invoke these endpoints using arbitrary asset identifiers, thus obtaining sensitive asset information like display names, reachability status, connection timing, and network addresses. Furthermore, malicious actors can initiate wake-on-LAN requests on unauthorized assets, potentially leading to further exploitation.
Affected Version(s)
next-terminal 0 <= 3.3.7-b1
