logo

Researchers warn of unpatched, critical Telnetd flaw affecting all versions

ID: 40ea93ed-045c-5107-b335-41d205a9979b

STIX ID: report--40ea93ed-045c-5107-b335-41d205a9979b

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-03-18

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

A critical buffer-overflow vulnerability (CVE-2026-32746, CVSS 9.8) in GNU InetUtils telnetd allows unauthenticated remote attackers to execute code as root via the LINEMODE SLC negotiation; the flaw affects all versions up to 2.7, can be triggered by a single connection to port 23, and places Linux distributions, IoT devices, and legacy OT/ICS systems at high risk. Researchers advise disabling Telnet, blocking port 23, enabling network monitoring and applying the forthcoming patch expected by April 1, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.