Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-24061 — Multi-threaded Telnet vulnerability scanner that exploits CVE-2026-24061 via environment variable injection, verifies root access, and provides an interactive shell on compromised hosts. | Kitploit
Tools/GitHubGitHub/kyukazamiqq/cve-2026-24061
Vulnerability ScannersExploitationNetwork SecurityPenetration TestingLearning & EducationRemote Access Tool
GitHubkyukazamiqq/cve-2026-24061

CVE-2026-24061

Multi-threaded Telnet vulnerability scanner that exploits CVE-2026-24061 via environment variable injection, verifies root access, and provides an interactive shell on compromised hosts.

View Repository
73 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Telnet Vulnerability Scanner & Exploiter

This Python script (main.py) is a multi-threaded tool designed to scan a list of target IPs/hostnames and attempt to exploit a specific vulnerability over Telnet.

[!WARNING] This tool is intended for educational purposes and authorized penetration testing only. Do not use it against systems you do not own or have explicit permission to test.

How it Works

The script attempts to connect to each target via Telnet and injects a malicious environment variable (USER=-f root) during the Telnet negotiation phase (IAC SB NEW-ENVIRON).

If the target server is vulnerable and improperly handles this environment variable (e.g., by passing it to a login process without sanitization), the script attempts to spawn a root shell. It verifies the exploit by executing id and whoami. If root access is confirmed, the script can provide an interactive session with the compromised host.

Features

  • Multi-threaded Scanning: Uses ThreadPoolExecutor to scan multiple targets concurrently for faster execution.
  • Automated Exploitation: Automatically crafts and sends the required Telnet negotiation payload.
  • Verification: Automatically runs basic commands to confirm root access.
  • Interactive Session: Drops the user into an interactive Telnet session upon successful exploitation.
  • Result Tracking: Saves successfully exploited targets to an output file (default: vulnerable.txt) in a thread-safe manner.

Requirements

  • Python 3.x
  • Standard library modules (telnetlib, sys, time, threading, concurrent.futures, socket)

Usage

python3 main.py <list.txt> [threads] [output.txt]

Arguments

  • list.txt (Required): A text file containing the targets to scan.
  • threads (Optional, Default: 5): The number of concurrent threads to use.
  • output.txt (Optional, Default: vulnerable.txt): The file where vulnerable targets will be saved.

Target List Format (list.txt)

The target list should contain one target per line. You can specify a custom port by appending :port. Lines starting with # are treated as comments.

# Example targets
192.168.1.1
192.168.1.2:2323
10.0.0.1
example.com:23

Example Commands

Basic scan with default settings (5 threads, output to vulnerable.txt):

python3 main.py targets.txt

Scan with 10 threads and output to results.txt:

python3 main.py targets.txt 10 results.txt
Download Tool