CVE-2026-58317 Details
Description
Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally.
A vulnerability allowing out-of-bounds read and write operations has been identified in the TTSSH2 plugin of Tera Term, affecting versions 1.00 alpha1 through 3.6.1. This vulnerability arises from an unsigned to signed conversion error, which can occur when Tera Term establishes an SSH connection to a server controlled by an attacker. The flaw may lead to the unintended transmission of adjacent memory contents to the server, causing Tera Term to behave unexpectedly or crash.
Users are advised to update to Tera Term 5.6.2, which includes the patched version of the TTSSH2 plugin. There are no plans to address this vulnerability in the Tera Term 4.x series.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 17, 2026CISA-ADP
Assessed Jul 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/jp/JVN65294474/ | [email protected] | AdvisoryBundleRemedy |
| https://teratermproject.github.io/SA/JVN65294474-en.html | [email protected] | AdvisoryRemedyVendor |
| https://teratermproject.github.io/SA/JVN65294474.html | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-196 | Unsigned to Signed Conversion Error | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| TeraTerm Project TTSSH2 | >= 1.00 alpha1, <= 3.6.1 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 17, 2026 | CVE Modified | CISA-ADP |
| Jul 17, 2026 | New CVE Received | [email protected] |
Volerion