Close Menu
  • Home
  • Opinion
  • Region
    • Africa
    • Asia
    • Europe
    • Middle East
    • North America
    • Oceania
    • South America
  • AI & Machine Learning
  • Robotics & Automation
  • Space & Deep Tech
  • Web3 & Digital Economies
  • Climate & Sustainability Tech
  • Biotech & Future Health
  • Mobility & Smart Cities
  • Global Tech Pulse
  • Cybersecurity & Digital Rights
  • Future of Work & Education
  • Trend Radar & Startup Watch
  • Creator Economy & Culture
What's Hot

Chinese language biotech startup Excalipoint banks $69M for next-gen T cell engagers

March 18, 2026

Brazil Fuels BYD Development within the Americas, Mexico & Argentina Place 100,000 Orders

March 18, 2026

BHIM Funds App Publicizes MS Dhoni as Model Ambassador

March 18, 2026
Facebook X (Twitter) Instagram LinkedIn RSS
NextTech NewsNextTech News
Facebook X (Twitter) Instagram LinkedIn RSS
  • Home
  • Africa
  • Asia
  • Europe
  • Middle East
  • North America
  • Oceania
  • South America
  • Opinion
Trending
  • Chinese language biotech startup Excalipoint banks $69M for next-gen T cell engagers
  • Brazil Fuels BYD Development within the Americas, Mexico & Argentina Place 100,000 Orders
  • BHIM Funds App Publicizes MS Dhoni as Model Ambassador
  • How Tubby Nugget Turned A Private Second Into A Rising Creator-Led Franchise
  • Koodo is as soon as once more giving prospects 25GB of free knowledge through textual content
  • Perfios appoints ex-SBI veteran Nitin Chugh as MD, group CEO
  • This analyst simply raised his value goal on MDA House
  • Vital Unpatched Telnetd Flaw (CVE-2026-32746) Permits Unauthenticated Root RCE
Wednesday, March 18
NextTech NewsNextTech News
Home - Cybersecurity & Digital Rights - Vital Unpatched Telnetd Flaw (CVE-2026-32746) Permits Unauthenticated Root RCE
Cybersecurity & Digital Rights

Vital Unpatched Telnetd Flaw (CVE-2026-32746) Permits Unauthenticated Root RCE

NextTechBy NextTechMarch 18, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Follow Us
Google News Flipboard
Vital Unpatched Telnetd Flaw (CVE-2026-32746) Permits Unauthenticated Root RCE
Share
Facebook Twitter LinkedIn Pinterest Email


Ravie LakshmananMar 18, 2026Vulnerability / Information Safety

Cybersecurity researchers have disclosed a crucial safety flaw impacting the GNU InetUtils telnet daemon (telnetd) that may very well be exploited by an unauthenticated distant attacker to execute arbitrary code with elevated privileges.

The vulnerability, tracked as CVE-2026-32746, carries a CVSS rating of 9.8 out of 10.0. It has been described as a case of out-of-bounds write within the LINEMODE Set Native Characters (SLC) suboption handler that ends in a buffer overflow, in the end paving the way in which for code execution.

Israeli cybersecurity firm Dream, which found and reported the flaw on March 11, 2026, mentioned it impacts all variations of the Telnet service implementation via 2.7. A repair for the vulnerability is anticipated to be out there no later than April 1, 2026.

“An unauthenticated distant attacker can exploit this by sending a specifically crafted message through the preliminary connection handshake — earlier than any login immediate seems,” Dream mentioned in an alert. “Profitable exploitation can lead to distant code execution as root.”

“A single community connection to port 23 is adequate to set off the vulnerability. No credentials, no person interplay, and no particular community place are required.”

The SLC handler, per Dream, processes choice negotiation through the Telnet protocol handshake. However on condition that the flaw may be triggered earlier than authentication, an attacker can weaponize it instantly after establishing a connection by sending specifically crafted protocol messages.

Profitable exploitation may end in full system compromise if telnetd runs with root privileges. This, in flip, may open the door to varied post-exploitation actions, together with the deployment of persistent backdoors, knowledge exfiltration, and lateral motion through the use of the compromised hosts as pivot factors.

“An unauthenticated attacker can set off it by connecting to port 23 and sending a crafted SLC suboption with many triplets,” in keeping with Dream safety researcher Adiel Sol.

“No login is required; the bug is hit throughout choice negotiation, earlier than the login immediate. The overflow corrupts reminiscence and may be changed into arbitrary writes. In apply, this could result in distant code execution. As a result of telnetd normally runs as root (e.g., beneath inetd or xinetd), a profitable exploit would give the attacker full management of the system.”

Within the absence of a repair, it is suggested to disable the service if it isn’t essential, run telnetd with out root privileges the place required, block port 23 on the community perimeter and host-based firewall stage to limit entry, and isolate Telnet entry.

The disclosure comes practically two months after one other crucial safety flaw was disclosed in GNU InetUtils telnetd (CVE-2026-24061, CVSS rating: 9.8) that may very well be leveraged to achieve root entry to a goal system. The vulnerability has since come beneath energetic exploitation within the wild, per the U.S. Cybersecurity and Infrastructure Safety Company.

Elevate your perspective with NextTech Information, the place innovation meets perception.
Uncover the most recent breakthroughs, get unique updates, and join with a worldwide community of future-focused thinkers.
Unlock tomorrow’s tendencies at present: learn extra, subscribe to our e-newsletter, and change into a part of the NextTech group at NextTech-news.com

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
NextTech
  • Website

Related Posts

CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths

March 17, 2026

Chrome Extension Turns Malicious After Possession Switch, Enabling Code Injection and Information Theft

March 17, 2026

Important n8n Flaws Permit Distant Code Execution and Publicity of Saved Credentials

March 16, 2026
Add A Comment
Leave A Reply Cancel Reply

Economy News

Chinese language biotech startup Excalipoint banks $69M for next-gen T cell engagers

By NextTechMarch 18, 2026

The funding, which ranks as one of many largest of its type for a China-based…

Brazil Fuels BYD Development within the Americas, Mexico & Argentina Place 100,000 Orders

March 18, 2026

BHIM Funds App Publicizes MS Dhoni as Model Ambassador

March 18, 2026
Top Trending

Chinese language biotech startup Excalipoint banks $69M for next-gen T cell engagers

By NextTechMarch 18, 2026

The funding, which ranks as one of many largest of its type…

Brazil Fuels BYD Development within the Americas, Mexico & Argentina Place 100,000 Orders

By NextTechMarch 18, 2026

Assist CleanTechnica’s work by means of a Substack subscription or on Stripe.…

BHIM Funds App Publicizes MS Dhoni as Model Ambassador

By NextTechMarch 18, 2026

Marks a strategic step in its subsequent section of progress centered on…

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

NEXTTECH-LOGO
Facebook X (Twitter) Instagram YouTube

AI & Machine Learning

Robotics & Automation

Space & Deep Tech

Web3 & Digital Economies

Climate & Sustainability Tech

Biotech & Future Health

Mobility & Smart Cities

Global Tech Pulse

Cybersecurity & Digital Rights

Future of Work & Education

Creator Economy & Culture

Trend Radar & Startup Watch

News By Region

Africa

Asia

Europe

Middle East

North America

Oceania

South America

2025 © NextTech-News. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms Of Service
  • Advertise With Us
  • Write For Us
  • Submit Article & Press Release

Type above and press Enter to search. Press Esc to cancel.

Subscribe For Latest Updates

Sign up to best of Tech news, informed analysis and opinions on what matters to you.

Invalid email address
 We respect your inbox and never send spam. You can unsubscribe from our newsletter at any time.     
Thanks for subscribing!