Unrated severityNVD Advisory· Published Jul 17, 2026· Updated Jul 17, 2026
CVE-2026-60060
CVE-2026-60060
Description
Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally.
Affected products
2Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.