PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73225 electerm CVE debrief

This PatchSiren debrief provides defensive context on CVE-2026-73225, a vulnerability in electerm, an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. The issue allows a malicious FTP or SFTP server to write attacker-controlled content outside the selected download directory due to unsanitized server-supplied file and folder names during recursive transfers.

Vendor
electerm
Product
Unknown
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-11
Original CVE updated
2026-09-09
Advisory published
2026-08-11
Advisory updated
2026-09-09

Who should care

Defenders responsible for systems using electerm for FTP or SFTP connections should assess exposure and prioritize verification and remediation. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify the version of electerm in use and upgrade to 3.15.120 or later if necessary. They should also monitor FTP and SFTP connections for suspicious activity and review compensating controls for ExPO-s

Why it matters

CVE-2026-73225 allows malicious FTP or SFTP servers to write outside download directories in electerm, requiring defenders to verify and upgrade to prevent potential data compromise.

  • Verify and upgrade to electerm version 3.15.120 or later to prevent potential data overwrite
  • Assess exposure for systems using electerm for FTP or SFTP connections to prevent potential data compromise
  • Monitor FTP and SFTP connections for suspicious activity to detect potential exploitation attempts

Technical summary

The electerm client is vulnerable to writing attacker-controlled content outside the selected download directory due to unsanitized server-supplied file and folder names during recursive transfers. This issue is fixed in electerm version 3.15.120. The vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. Defenders should prioritize verifying and upgrading to electerm version 3.15.120 or later, and assess exposure for systems using electerm for FTP or SFTP connections. The vulnerability can be exploited by a malicious FTP or SFTP server, allowing it to write outside the download directory.

Defensive priority

Defenders should prioritize verifying and upgrading to electerm version 3.15.120 or later, and assess exposure for systems using electerm for FTP or SFTP connections.

Recommended defensive actions

  • Verify electerm version and upgrade to 3.15.120 or later
  • Assess exposure for systems using electerm for FTP or SFTP connections
  • Monitor FTP and SFTP connections for suspicious activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 8.1 and HIGH severity. The issue is fixed in electerm version 3.15.120. Defenders should verify the version of electerm in use and upgrade to 3.15.120 or later if necessary. The vulnerability allows a malicious FTP or SFTP server to write attacker-controlled content outside the selected download directory due to unsanitized server-supplied file and folder names during recursive transfers.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73225 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73225

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73225 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73225

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.