Vulnerability record · CVE-2005-0768 · published 2 May 2005
CVE-2005-0768: GoodTech Telnet Server admin web server buffer overflow
Goodtech Systems · Goodtech Telnet Server
The administration web server in GoodTech Telnet Server 4.0 and 5.0 (and possibly all versions before 5.0.7) contains a buffer overflow reachable via a long string sent to port 2380. A remote, unauthenticated attacker can trigger the overflow and execute arbitrary code on the host.
Description
Buffer overflow in the administration web server for GoodTech Telnet Server 4.0 and 5.0, and possibly all versions before 5.0.7, allows remote attackers to execute arbitrary code via a long string to port 2380.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityThe flaw is remotely exploitable without authentication, has complete impact per CVSS 2.0, public exploit code exists and EPSS is very high.
What it is
The administration web server in GoodTech Telnet Server 4.0 and 5.0 (and possibly all versions before 5.0.7) contains a buffer overflow reachable via a long string sent to port 2380. A remote, unauthenticated attacker can trigger the overflow and execute arbitrary code on the host.
Impact
Successful exploitation gives the attacker arbitrary code execution with the privileges of the administration web server, typically full control of the affected system. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.
Attack surface
The flaw is reached over the network by sending a crafted long string to TCP port 2380, the administration web server. The CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
No CISA KEV listing and no ransomware association are recorded, but public exploit code is referenced and EPSS is high (0.5953, 99th percentile), indicating elevated likelihood of exploitation.
What to do
- Upgrade GoodTech Telnet Server to version 5.0.7 or later, which the description indicates fixes the issue.
- If upgrading is not possible, block or restrict access to TCP port 2380 to trusted management hosts only.
- Disable the administration web server if it is not required for operations.
- Segment or isolate hosts running the affected Telnet server to limit lateral movement after compromise.
- Monitor vendor advisories for any backported fix if the product remains supported.
Detection
- Inspect network traffic to TCP port 2380 for unusually long request strings or malformed HTTP-like input.
- Alert on crashes, restarts or abnormal process behavior of the GoodTech administration web server.
- Review host logs for unexpected child processes or command execution originating from the Telnet server service.
- Use IDS/IPS signatures for buffer overflow attempts against the GoodTech admin web server on port 2380.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-0768 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2005-0768), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.