Hacking a Tenda AC1200 Wi-Fi Router with a CVE Combo https://hackaday.com/2026/08/05/hacking-a-tenda-ac1200-wi-fi-router-with-a-cve-combo/
#ReverseEngineering #SecurityHacks #Routerhacking #Telnet #Tenda #Uart
#telnet
9 posts · Last used Aug 06
OK. Well-written malware. I get that.
But am I the only one who’s surprised that Telnet is still running anywhere at all, and that this is what made the compromise possible in the first place? Sure. It was a honeypot. But the developers of this malware aren’t just targeting honeypots; they’re also after ‘real’ systems.
If only someone would develop something like VPNs.
https://www.nozominetworks.com/blog/tengu-a-modernized-mirai-that-doesnt-want-to-leave
#mirai #malware #wtf #iot #linux #telnet
BREAKING: Bueno, tenemos el agrado de anunciar oficialmente la inauguración de la comunidad Tilde Undernet, para poner en alto los servicios de texto plano, para los amantes del minimalismo y la línea de comandos. Estamos en etapa de pruebas, los registros son solo por recomendación de un usuario existente y son aprobados manualmente y la vía de contacto figura en la capsula gemini de la comunidad. Disponemos de capsulas gemini para usuarios, servidor de noticias NNTP/Usenet, IRC, Telnet BBS, clientes XMPP, lectores de noticias RSS y mucho más. Tenemos una landing page en gemini://undernet.uy #gemini #textoplano #tilde #comunidad #commandline #cli #consola #terminal #ssh #telnet #pubnix #undernet #uruguay #nntp #usenet #capsule
Replying to
The Telnet port in 2026 is not a relic.
Three simultaneous populations: IoT botnets with hex-encoded auth probes, router scanners with device-specific credential lists, occasional human operators.
All three attracted by one honeypot emulating a BusyBox router.
Full report + analysis scripts:
github.com/dblanko/honeypot-analysis
Full post: sshlab.eu/blog/260000-telnet-connections-in-72-hours-iot-honeypot-data-59e3b901
#honeypot #iot #telnet #infosec #threatintelligence #mirai
2026-01-14: Il giorno in cui telnet morì
Il 14 gennaio 2026, il traffico #telnet globale osservato dai sensori di GreyNoise è crollato. Una riduzione sostenuta del 59%, diciotto ASN completamente silenziosi e cinque paesi completamente scomparsi dai nostri dati. Sei giorni dopo, la CVE-2026-24061 è scomparsa. La coincidenza è una delle possibili spiegazioni.
https://www.labs.greynoise.io/grimoire/2026-02-10-telnet-falls-silent/
@informatica
800K Linux servers with a Telnet vulnerability. Unless you need it to talk to some legacy systems, turn Telnet off, it's 2026.
https://www.youtube.com/watch?v=81fq__6a1FQ
#Telnet #Vulnerability
Critical Linux Warning: 800,000 Devices Are EXPOSED
Nearly 800,000 #Telnet servers exposed to remote attacks
The security flaw (CVE-2026-24061) already has a proof-of-concept exploit, impacts GNU InetUtils versions 1.9.3 (released in 2015) through 2.7, and was patched in version 2.8 (released on January 20).
https://www.bleepingcomputer.com/news/security/nearly-800-000-telnet-servers-exposed-to-remote-attacks/
🚨 Critical #Telnet Authentication Bypass Vulnerability Discovered #CVE202624061 #cybersecurity #infosec #DevOps #security
🔓 #GNU Inetutils telnetd through version 2.7 allows remote authentication bypass via "-f root" USER environment variable
⚡ The exploit is shockingly simple: attackers send "-f root" as the USER value, triggering /usr/bin/login -f root which skips password authentication entirely
🧵 👇
You've seen all posts
