VYPR
Critical severityNVD Advisory· Published Jan 20, 2023· Updated Apr 3, 2025

CVE-2020-23256

CVE-2020-23256

Description

Electerm 1.3.22 lacks permission checks on its internal service, allowing remote attackers to execute arbitrary commands via unverified requests.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Electerm 1.3.22 lacks permission checks on its internal service, allowing remote attackers to execute arbitrary commands via unverified requests.

Electerm 1.3.22 contains a critical security vulnerability where the application fails to verify the origin of requests made to its internal service. This allows an attacker to send unauthenticated requests that can execute arbitrary commands on the host system [1][3][4]. The root cause is the absence of permission checks on the service endpoint, which trusts any incoming request without validation.

To exploit this vulnerability, an attacker must lure a user who has Electerm running to visit a malicious website. The malicious site can then send crafted requests to Electerm's internal service, triggering command execution without any user interaction beyond keeping the application open [4]. No authentication or special network position is required; the attack works across all supported operating systems.

Successful exploitation grants the attacker arbitrary code execution with the privileges of the Electerm process. This can lead to full system compromise, including data theft, installation of malware, or further lateral movement within the network [3]. The vulnerability is rated as critical severity.

Users should update Electerm to a version later than 1.3.22, as the advisory indicates that versions up to and including 1.3.22 are affected [3]. No official workaround has been provided, but generating a random token for service invocation at startup has been suggested as a mitigation [4].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
electermnpm
<= 1.3.22

Affected products

2
  • Electerm/Electermcpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: =1.3.22

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.