Critical Telnetd Bug: Unauthenticated Root RCE via Port 23 (CVE-2026-32746). Patch Now!
Mar 18, 2026 // 13:24 - Niko Dunn


Security experts have revealed a serious vulnerability in the GNU InetUtils telnet daemon (telnetd). This flaw could allow an unauthorized remote attacker to run any code with administrator-level access.

The vulnerability, identified as CVE-2026-32746, has a high severity score of 9.8 out of 10.0. It involves an out-of-bounds write error in the LINEMODE Set Local Characters (SLC) handler, leading to a buffer overflow that enables code execution.

Dream, an Israeli cybersecurity firm that found and reported the vulnerability on March 11, 2026, stated that it affects all Telnet service versions up to 2.7. A patch for the vulnerability is anticipated to be released by April 1, 2026.

“Exploitation is possible by an unauthenticated remote attacker who sends a malicious message during the initial connection phase, before any login is required,” Dream reported. “Successful exploitation allows for remote code execution as root user.”

“A single network connection to port 23 is enough to trigger this vulnerability. No login credentials, user interaction, or privileged network location are necessary.”

Dream explains that the SLC handler manages option negotiations during the Telnet handshake. Because the flaw can be triggered before anyone logs in, an attacker can exploit it immediately after establishing a connection by sending specially crafted protocol messages.

If telnetd runs with root privileges, successfully exploiting this flaw could completely compromise the system. This could then permit post-exploitation activities, like installing persistent backdoors, stealing data, and moving through the network by using the compromised system as a pivot.

“An attacker without credentials can trigger this by connecting to port 23 and sending a crafted SLC suboption containing numerous triplets,” according to Dream security researcher Adiel Sol, as stated.

“No login is needed since the bug is triggered during option negotiation, before the login prompt. The overflow corrupts memory and can be transformed into arbitrary memory writes. This can lead to remote code execution. Because telnetd typically runs as root user, a successful exploit would grant the attacker full control of the system.”

If a fix isn’t available, it’s recommended to disable the service if it’s not essential, run telnetd without root access when it is necessary, block port 23 via network and host firewalls to limit access, and isolate Telnet access.

This disclosure follows the discovery of another critical vulnerability in GNU InetUtils telnetd (CVE-2026-24061, CVSS score: 9.8) roughly two months ago. That flaw could also be used to gain root access to a target system, and the U.S. Cybersecurity and Infrastructure Security Agency has noted that it is actively being exploited.

#bug  #critical  #cve-2026-32746)  #news  #now  #patch  #port  #rce  #root  #telnetd  #unauthenticated  #via   —   News