← Vulnerability feed

Vulnerability record · CVE-2005-0768 · published 2 May 2005

CVE-2005-0768: GoodTech Telnet Server admin web server buffer overflow

Goodtech Systems · Goodtech Telnet Server

The administration web server in GoodTech Telnet Server 4.0 and 5.0 (and possibly all versions before 5.0.7) contains a buffer overflow reachable via a long string sent to port 2380. A remote, unauthenticated attacker can trigger the overflow and execute arbitrary code on the host.

10.0 CVSS 2.0 High EPSS 60% · top 0.9%
10.0CVSS 2.0 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the administration web server for GoodTech Telnet Server 4.0 and 5.0, and possibly all versions before 5.0.7, allows remote attackers to execute arbitrary code via a long string to port 2380.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityThe flaw is remotely exploitable without authentication, has complete impact per CVSS 2.0, public exploit code exists and EPSS is very high.

What it is

The administration web server in GoodTech Telnet Server 4.0 and 5.0 (and possibly all versions before 5.0.7) contains a buffer overflow reachable via a long string sent to port 2380. A remote, unauthenticated attacker can trigger the overflow and execute arbitrary code on the host.

Impact

Successful exploitation gives the attacker arbitrary code execution with the privileges of the administration web server, typically full control of the affected system. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.

Attack surface

The flaw is reached over the network by sending a crafted long string to TCP port 2380, the administration web server. The CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.

Exploitation

No CISA KEV listing and no ransomware association are recorded, but public exploit code is referenced and EPSS is high (0.5953, 99th percentile), indicating elevated likelihood of exploitation.

What to do

  • Upgrade GoodTech Telnet Server to version 5.0.7 or later, which the description indicates fixes the issue.
  • If upgrading is not possible, block or restrict access to TCP port 2380 to trusted management hosts only.
  • Disable the administration web server if it is not required for operations.
  • Segment or isolate hosts running the affected Telnet server to limit lateral movement after compromise.
  • Monitor vendor advisories for any backported fix if the product remains supported.

Detection

  • Inspect network traffic to TCP port 2380 for unusually long request strings or malformed HTTP-like input.
  • Alert on crashes, restarts or abnormal process behavior of the GoodTech administration web server.
  • Review host logs for unexpected child processes or command execution originating from the Telnet server service.
  • Use IDS/IPS signatures for buffer overflow attempts against the GoodTech admin web server on port 2380.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-0768 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2005-0768), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.