Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Terrminus-CVE-2026-2406 — AsyncIO Scanner & Exploitation Framework for CVE-2026-24061 (Telnet NEW_ENVIRON Auth Bypass). Features high-concurrency discovery, passive fingerprinting, and authorized root shell escalation | Kitploit
Tools/GitHubGitHub/ridpath/terrminus-cve-2026-2406
Privilege EscalationReconnaissanceVulnerability ScannersIoT SecurityExploitationSCADA/ICS SecurityInformation GatheringWeb SecurityNetwork Security

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Penetration Testing
Red Teaming
GitHubridpath/terrminus-cve-2026-2406

Terrminus-CVE-2026-2406

AsyncIO Scanner & Exploitation Framework for CVE-2026-24061 (Telnet NEW_ENVIRON Auth Bypass). Features high-concurrency discovery, passive fingerprinting, and authorized root shell escalation

View Repository
2298 months agoNot yet reviewed

Terminus - CVE-2026-24061 Scanner & Exploitation Framework

A security analysis engine for CVE-2026-24061 Telnet NEW_ENVIRON authentication bypass and privilege escalation vulnerability.

Terminus


Overview

Terminus is a professional security research tool designed for authorized penetration testing and vulnerability assessment of CVE-2026-24061. This critical vulnerability affects legacy Telnet daemon implementations, allowing unauthenticated remote attackers to bypass authentication and gain root-level access.

What is CVE-2026-24061?

CVE-2026-24061 is a Remote Code Execution vulnerability in Telnet services that support RFC 1572 (Telnet Environment Option). The vulnerability exploits improper sanitization of the USER environment variable during NEW_ENVIRON subnegotiation:

  • Normal authentication: USER=john → prompts for password
  • Exploit payload: USER=-f root → bypasses authentication, grants root shell

Impact:

  • Complete authentication bypass (no password required)
  • Immediate privilege escalation to root
  • Full system compromise

Affected Services:

  • Legacy Telnet GNU Inetutils telnetd (specifically versions through 2.7)
  • IoT firmware with vulnerable Telnet implementations
  • Industrial control systems with outdated Telnet services

Key Features

Mass Vulnerability Scanner

  • High-Concurrency Scanning: Scan 1,000+ targets concurrently using AsyncIO
  • CIDR Support: Scan entire network ranges (192.168.0.0/24, 10.0.0.0/8)
  • Dual Detection Modes:
    • Passive (default): Fast, safe, signature-based detection
    • Active Verification (--verify): Proof-of-exploit, confirms uid=0 root access
  • Banner Analysis: Fingerprint daemon types and versions
  • Risk Scoring: Multi-layered confidence assessment (CRITICAL, HIGH, MEDIUM, LOW)

RFC-Compliant Protocol Engine

  • TerminusNegotiator Class: Clean API for Telnet protocol operations
    • Terminus.handshake() - RFC 854 compliant handshake
    • Terminus.exploit() - CVE-2026-24061 payload delivery
  • Proper Option Negotiation: Avoids IDS/IPS detection through protocol compliance
  • State Machine: Robust handling of IAC sequences (DO/DONT/WILL/WONT/SB/SE)

Authorization-Gated Exploitation

  • Interactive Shell: Full post-exploitation shell with root access
  • Command Execution: Execute single commands and capture output
  • Evidence Collection: Gather uid, environment variables, system info
  • Safety Mechanisms:
    • Requires explicit --exploit flag
    • Disabled in batch scanning mode
    • Audit logging of all exploitation attempts

Multi-Format Reporting

  • Terminal: Rich-formatted tables with color-coded risk levels
  • JSON: SIEM/SOAR integration
  • CSV: Spreadsheet tracking
  • HTML: Detailed reports with statistics
  • Markdown: Documentation-friendly output

Architecture

Core Engine: TerminusNegotiator

The heart of Terminus is the TerminusNegotiator class, which provides a clean separation between protocol handling and exploitation logic:

from terminus import TerminusNegotiator

# Initialize engine
negotiator = TerminusNegotiator()

# Step 1: RFC 854 compliant handshake
await negotiator.handshake(target="192.168.1.100", port=23)

# Step 2: Deliver CVE-2026-24061 payload
result = await negotiator.exploit(payload="-f root")

if result.success:
    print(f"Root shell acquired: {result.evidence['uid']}")

Engine vs. Script Approach

Traditional scripts (existing tools):

Target → Raw Socket → Payload → Blind Execution → Hope for Shell

Terminus engine:

Target → Discovery → RFC Handshake → Passive Analysis → Risk Assessment
                                    ↓
                          [Optional] Verified Exploitation → Evidence Collection → Report

Installation

Requirements

  • Python 3.10+
  • Supported Platforms:
    • Windows 10/11 (PowerShell)
    • Windows + WSL2 (Kali Linux, Parrot OS, Ubuntu)
    • Native Linux (Kali, Parrot, Ubuntu, Debian)
    • macOS (with Python 3.10+)

Quick Start (All Platforms)

Windows (PowerShell)

# Clone repository
git clone https://github.com/ridpath/Terrminus-CVE-2026-2406.git

# Run setup script
.\setup_env.ps1

# Activate virtual environment
.venv\Scripts\Activate.ps1

# Verify installation
terminus --version

Linux / WSL2 / macOS (Bash)

# Clone repository
git clone https://github.com/ridpath/Terrminus-CVE-2026-2406.git
cd Terminus-CVE-2025-2406

# Run setup script
chmod +x setup_env.sh
./setup_env.sh
Download Tool