Critical Telnet Vulnerability: Code Execution Without Authentication

A critical vulnerability has been discovered in GNU InetUtils (telnetd), tracked as CVE-2026-32746, which breaks the standard attack model. Typically, an attacker would need to provide valid credentials or perform a brute-force attack—but this flaw bypasses those requirements entirely.
An attacker only needs to connect to port 23 and send a specially crafted packet during the initial option negotiation, prior to the login prompt. The vulnerability exists in the handling of the LINEMODE suboption, where improper input validation leads to a buffer overflow.
💬 Discuss
Vulnerabilities
10
CVE-2026-32746
Researchers
Adiel Sol
Arad Inbar
Ben Grinberg
Daniel Lubel
Dream Security Research Team
Erez Cohen
More
Vendors
Gnu
Products
Gnu Inetutils
Telnet
Telnetd
Published
2026-03-23, 12:14