Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Pokémon Center Data Breach Exposes Customer PII to Hackers
August 18, 2026
Best Software-Defined Perimeter (SDP) Solutions of 2024
August 17, 2026
Threema Messaging Service Suffers Massive DDoS Attack
August 17, 2026
Home/CyberSecurity News/Critical Telnetd CVE-2024-XXXXX lets attackers run code via port 23
CyberSecurity News

Critical Telnetd CVE-2024-XXXXX lets attackers run code via port 23

Key Takeaways A critical buffer overflow vulnerability (CVE-2026-32746) has been discovered in the GNU Inetutils telnetd daemon. The flaw allows unauthenticated remote attackers to execute arbitrary...

David kimber
David kimber
March 18, 2026 3 Min Read
48 0

Key Takeaways

  • A critical buffer overflow vulnerability (CVE-2026-32746) has been discovered in the GNU Inetutils telnetd daemon.
  • The flaw allows unauthenticated remote attackers to execute arbitrary code and gain root access on affected systems without user interaction.
  • The vulnerability is particularly dangerous for legacy infrastructure, including Industrial Control Systems (ICS) and Operational Technology (OT), where Telnet is still prevalent.
  • A patch is expected by April 1, 2026, but immediate mitigations are crucial due to the ease of exploitation.

A severe buffer overflow vulnerability has been uncovered in the GNU Inetutils telnetd daemon, posing a critical threat to systems still relying on the legacy Telnet protocol. Identified as CVE-2026-32746, this flaw allows an unauthenticated remote attacker to execute arbitrary code and achieve root-level compromise on vulnerable machines.

Table Of Content

  • Key Takeaways
  • Telnetd Vulnerability Enables Remote Attack
  • Mitigation Strategies
  • What You Should Do

The vulnerability’s exploitation path is considered trivial, requiring zero user interaction. This ease of exploitation has prompted an urgent alert for cybersecurity professionals managing older network infrastructure.

According to research from Dream Security, the root cause of the issue lies in how the telnetd daemon processes LINEMODE SLC (Set Local Characters) option negotiations.

Attackers can trigger the classic buffer overflow by transmitting a specially crafted message during the initial connection handshake. Since this occurs before any authentication prompt appears, no valid credentials are required for a successful exploit. Dream Security researchers informed the GNU Inetutils team about the vulnerability on March 11, 2026.

Telnetd Vulnerability Enables Remote Attack

Maintainers quickly verified the discovery and approved a patch, which is anticipated to be officially released on April 1, 2026.

While there have been no reports of active exploitation in the wild, the low complexity of the attack necessitates immediate defensive measures.

Despite modern IT environments largely favoring SSH over Telnet, the plaintext protocol remains deeply embedded in various sectors, including Industrial Control Systems (ICS), Operational Technology (OT), and government networks.

Many aging Programmable Logic Controllers (PLCs) and SCADA systems still rely on Telnet as their primary remote management interface. Upgrading these critical systems often involves significant costs and operational disruptions, frequently leading organizations to accept prolonged exposure to such vulnerabilities.

Given that the telnetd service commonly runs with root privileges via inetd or xinetd, a successful exploit grants an attacker complete control over the host. This level of access could allow adversaries to install persistent backdoors, exfiltrate sensitive operational data, or use the compromised device as a springboard for deeper intrusions into physical infrastructure, such as manufacturing lines, water treatment facilities, or power grids.

Mitigation Strategies

With a formal patch still pending, security teams must implement immediate workarounds to protect exposed systems. The most effective defense is to disable the telnetd service entirely. If operational requirements mandate its continued use, network administrators should block port 23 at the perimeter firewall, restricting access solely to trusted hosts.

Running telnetd with reduced privileges, rather than as root, can also limit the potential impact of a successful exploit.

Dream Security researchers emphasize that standard authentication logs will not capture this attack because it occurs during the initial option negotiation phase. Therefore, defenders must rely on network-level logging and packet capture for threat detection.

What You Should Do

  • Disable Telnetd: If possible, completely disable the telnetd service on all systems.
  • Block Port 23: Implement firewall rules to block inbound connections to port 23 from untrusted networks. Restrict access to only necessary, trusted hosts.
  • Limit Privileges: If telnetd must remain active, configure it to run with the lowest possible privileges, ideally not as root.
  • Monitor Network Traffic: Configure firewalls to log all new connections to port 23. Deploy Intrusion Detection System (IDS) signatures to alert on LINEMODE SLC suboptions with unusually large payloads (exceeding 90 bytes).
  • Centralize Logs: Forward all security logs, especially network and system logs, to a centralized SIEM (Security Information and Event Management) system to prevent attackers from tampering with forensic evidence after a compromise.
  • Prepare for Patch: Monitor for the official patch release (expected April 1, 2026) and apply it immediately upon availability.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCVEExploitPatchSecurityThreatVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Critical ScreenConnect Vulnerability Lets Attackers Extract Keys, Hijack Sessions

Next Post

Apple Patches Critical WebKit Bug CVE-2023-42916 Allowing Code Execution

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Microsoft SCCM Vulnerability Lets Attackers Execute Remote Code
August 17, 2026
Z.ai Launches GLM-5.3, Boosting Cybersecurity and Coding Capabilities
August 17, 2026
Critical GeoServer SQLi Vulnerability Allows Remote Code Execution
August 17, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us