Es un protocolo aún utilizado en dispositivos de poca potencia como algunos routers, robots, etc.
Revisad vuestro router y desactivad Telnet.
thehackernews.com/2026/03/crit...
Es un protocolo aún utilizado en dispositivos de poca potencia como algunos routers, robots, etc.
Revisad vuestro router y desactivad Telnet.
thehackernews.com/2026/03/crit...
Patient: I can't wait to go home and $(telnetd -lsh -p6969)
House:
Patient: I can't wait to go home and $(telnetd -lsh -p6969)
House:
(if anyone's wondering why there's telnet when I said no telnet, it's because the first thing I did was drop busybox and spawn a proper telnetd)
(also if anyone's wondering what you'd do with a rooted r1, I haven't figured that part out yet)
(if anyone's wondering why there's telnet when I said no telnet, it's because the first thing I did was drop busybox and spawn a proper telnetd)
(also if anyone's wondering what you'd do with a rooted r1, I haven't figured that part out yet)
github.com/leonjza/inet...
₁ seclists.org/oss-sec/2026...
github.com/leonjza/inet...
₁ seclists.org/oss-sec/2026...
The vulnerability went unnoticed for nearly 11 years.
👇
The vulnerability went unnoticed for nearly 11 years.
👇
Vulnerabilità in GNU Inetutils telnetd e rischi strutturali del protocollo Telnet
#infosec
www.acn.gov.it/portale/w/vu...
Vulnerabilità in GNU Inetutils telnetd e rischi strutturali del protocollo Telnet
#infosec
www.acn.gov.it/portale/w/vu...
Have ordered another to try ;telnetd; instead
Have ordered another to try ;telnetd; instead
"The flaw occurs because telnetd passes the user-controlled USER environment variable directly to login(1) without sanitization."
And OSS is more secure? Can't be more secure if you don't have the eyes to find flaws.
www.bleepingcomputer.com/news/securit...
"The flaw occurs because telnetd passes the user-controlled USER environment variable directly to login(1) without sanitization."
And OSS is more secure? Can't be more secure if you don't have the eyes to find flaws.
www.bleepingcomputer.com/news/securit...
marc.info?l=openbsd-cv...
FreeBSD, in 2022: "Time for a stern deprecation notice in the man page."
marc.info?l=openbsd-cv...
FreeBSD, in 2022: "Time for a stern deprecation notice in the man page."
seclists.org/oss-sec/2026...
seclists.org/oss-sec/2026...
www.openwall.com/lists/oss-se...
www.openwall.com/lists/oss-se...
www.cert.ssi.gouv.fr/actualite/CE...
www.cert.ssi.gouv.fr/actualite/CE...