Skip to content

安全公告:GNU Inetutils telnetd 危急漏洞

GNU Inetutils telnetd 伺服器發現多項危急漏洞,影響大多數現代 Linux 部署。這些缺陷允許攻擊者在顯示登入提示前,即可繞過身分驗證並執行遠端程式碼 (RCE)。

狀態:目前尚無修補程式。 強烈建議立即在所有受影響的主機上停用 Telnet 服務。

漏洞摘要

漏洞類型編號CVSS 分數受影響版本
SLC 緩衝區溢位尚未指派危急 (Critical)2.7 及更早版本
身分驗證繞過 ($USER 變數)CVE-2026-240619.81.9.3 及更高版本

使用 runZero 進行識別

請在您的資產清單 (Asset Inventory) 中使用以下查詢語句來尋找可能受影響的 Linux 系統:

_asset.protocol:=telnet AND protocol:=telnet AND os:Linux AND banner:=”%login:” AND NOT banner:busybox

建議採取行動

  • 在整個網路中停用 telnetd 服務。
  • 確保實施嚴格的網路存取控制(防火牆)。
  • 將遠端管理工具更換為具備加密功能的 SSH

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×