logo

PoC Released for GNU InetUtils telnetd RCE as 800K+ Exposed Instances Remain Online

ID: 02b93ae8-9fe6-5d0c-9dc4-1d769241423a

STIX ID: report--02b93ae8-9fe6-5d0c-9dc4-1d769241423a

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-01-26

Date Updated: 2026-04-22

Author: Divya

...
...

A proof-of-concept exploit for CVE-2026-24061 (critical RCE) in GNU Inetutils telnetd has been published, and researchers report roughly 800,000 telnet instances exposed on port 23/TCP worldwide; the vulnerability permits unauthenticated arbitrary command execution, making exposed legacy telnet services high-value targets for credential harvesting and lateral movement. The report urges organizations to audit and remove exposed telnet services, migrate to SSH, apply firewall restrictions, and monitor for mass-exploitation activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.