Vulnerability record · CVE-2020-10188 · published 6 March 2020
CVE-2020-10188: netkit telnetd buffer overflow allows remote code execution
NNetkit Telnet Project · Netkit Telnet
A buffer overflow in utility.c in netkit telnetd through 0.17, involving the netclear and nextitem functions, can be triggered by short writes or urgent data. It is remotely reachable over the network without authentication, and the affected telnetd is bundled in multiple Linux distributions and network operating systems, so exposure is broad wherever the service is enabled.
Description
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, and full code execution impact, combined with a very high EPSS score, makes this a top remediation priority despite no KEV listing.
What it is
A buffer overflow in utility.c in netkit telnetd through 0.17, involving the netclear and nextitem functions, can be triggered by short writes or urgent data. It is remotely reachable over the network without authentication, and the affected telnetd is bundled in multiple Linux distributions and network operating systems, so exposure is broad wherever the service is enabled.
Impact
An unauthenticated remote attacker can execute arbitrary code in the context of the telnetd service, typically root, giving full control of the host.
Attack surface
Reachable over the network via the telnet service (CVSS AV:N, PR:N, UI:N); no authentication or user interaction is required, only the ability to send crafted telnet data to the listening daemon.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is very high (0.743, 99.5th percentile), indicating elevated likelihood of exploitation activity. Multiple vendor advisories and patch references exist, confirming the flaw is well known.
What to do
- Apply the vendor patch for netkit telnetd or the fixed package from your distribution (Debian, Fedora, Oracle, Arista, Juniper advisories list fixes).
- Disable or remove the telnetd service where it is not strictly required; replace with SSH for remote administration.
- Restrict network access to telnet ports (TCP/23) with firewall rules and network segmentation so only trusted management hosts can connect.
- If telnetd cannot be removed, run it with least privilege and monitor for unexpected child processes or crashes.
- Track vendor advisories for embedded telnetd in network devices (Arista EOS, Juniper Junos, Oracle products) and patch firmware accordingly.
Detection
- Monitor telnet service logs and process accounting for telnetd crashes, restarts, or abnormal child processes spawned by telnetd.
- Inspect network traffic to TCP/23 for malformed telnet option negotiations, urgent (OOB) data, or unusually short writes that may indicate exploitation attempts.
- Alert on unexpected outbound connections or shell activity originating from hosts running telnetd.
- Use host-based detection for memory corruption indicators such as segfaults in telnetd and unexpected file or process creation under the telnetd account.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-10188 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-10188), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.