
Multi-threaded Telnet vulnerability scanner that exploits CVE-2026-24061 via environment variable injection, verifies root access, and provides an interactive shell on compromised hosts.
This Python script (main.py) is a multi-threaded tool designed to scan a list of target IPs/hostnames and attempt to exploit a specific vulnerability over Telnet.
[!WARNING] This tool is intended for educational purposes and authorized penetration testing only. Do not use it against systems you do not own or have explicit permission to test.
The script attempts to connect to each target via Telnet and injects a malicious environment variable (USER=-f root) during the Telnet negotiation phase (IAC SB NEW-ENVIRON).
If the target server is vulnerable and improperly handles this environment variable (e.g., by passing it to a login process without sanitization), the script attempts to spawn a root shell. It verifies the exploit by executing id and whoami. If root access is confirmed, the script can provide an interactive session with the compromised host.
ThreadPoolExecutor to scan multiple targets concurrently for faster execution.vulnerable.txt) in a thread-safe manner.telnetlib, sys, time, threading, concurrent.futures, socket)python3 main.py <list.txt> [threads] [output.txt]
list.txt (Required): A text file containing the targets to scan.threads (Optional, Default: 5): The number of concurrent threads to use.output.txt (Optional, Default: vulnerable.txt): The file where vulnerable targets will be saved.list.txt)The target list should contain one target per line. You can specify a custom port by appending :port. Lines starting with # are treated as comments.
# Example targets
192.168.1.1
192.168.1.2:2323
10.0.0.1
example.com:23
Basic scan with default settings (5 threads, output to vulnerable.txt):
python3 main.py targets.txt
Scan with 10 threads and output to results.txt:
python3 main.py targets.txt 10 results.txt