Eternal Terminal Project maintains a narrowly scoped terminal-emulation and remote-access utility that serves as an alternative to SSH, with its vulnerability profile centered on the single eternal_terminal product. The durable signal across its disclosures reflects the complexity of parsing untrusted network input and managing concurrent connections: recurrent weakness classes include race conditions, classic buffer overflows, improper input validation, sensitive-information exposure, and symlink-following issues that are characteristic of low-level network and file handling code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eternal Terminal Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24949HIGH A privilege escalation to root exists in Eternal Terminal prior to version 6.2.0. This is due to the combination of a race condition, buffer overflow, and logic bug all in PipeSock | Aug 16, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-24951HIGH A race condition exists in Eternal Terminal prior to version 6.2.0 which allows a local attacker to hijack Eternal Terminal's IPC socket, enabling access to Eternal Terminal client | Aug 16, 2022 | 7.0 | 24 | NO | NO |
CVE-2022-24952MEDIUM Several denial of service vulnerabilities exist in Eternal Terminal prior to version 6.2.0, including a DoS triggered remotely by an invalid sequence number and a local bug trigger | Aug 16, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-48258MEDIUM In Eternal Terminal 6.2.1, etserver and etclient have world-readable logfiles. | Jan 13, 2023 | 5.3 | 20 | NO | NO |
CVE-2022-48257MEDIUM In Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp. | Jan 13, 2023 | 5.3 | 20 | NO | NO |
CVE-2022-24950HIGH A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other users' SSH authorization socket, enabling the attacker to l | Aug 16, 2022 | 7.5 | 19 | NO | NO |
CVE-2023-23558MEDIUM In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode 0777 before the etserver proce | Feb 16, 2023 | 6.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eternal Terminal Project.
Media articles that mention a CVE ID that affects a product developed by Eternal Terminal Project — matched by CVE ID, not by vendor name.