Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally.
History

Sat, 01 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Handling in TTSSH2 Plugin May Lead to Information Disclosure

Tue, 28 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read/Write in TTSSH2 Plugin Causing Information Leakage

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Teraterm Project
Teraterm Project ttssh2
Vendors & Products Teraterm Project
Teraterm Project ttssh2

Wed, 22 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read/Write in TTSSH2 Plugin Causing Information Leakage

Fri, 17 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Description Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally.
Weaknesses CWE-130
References
Metrics cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2026-07-17T04:13:38.109Z

Updated: 2026-07-17T13:09:30.703Z

Reserved: 2026-07-10T02:15:09.033Z

Link: CVE-2026-60060

cve-icon Vulnrichment

Updated: 2026-07-17T13:09:18.400Z

cve-icon NVD

No data.

cve-icon Redhat

No data.