Dream Security flags critical RCE vulnerability in GNU Inetutils telnetd, exposing ICS and OT systems
Dream Security Labs published a vulnerability advisory detailing a pre-authentication remote code execution flaw caused by a buffer overflow in the telnetd LINEMODE SLC handler. The research uncovered a critical buffer overflow vulnerability, CVE-2026-32746, in the GNU Inetutils telnetd daemon, specifically within the LINEMODE SLC option negotiation handler. An unauthenticated remote attacker can exploit the flaw by sending a specially crafted message during the initial connection handshake, before any login prompt appears, potentially achieving remote code execution with root privileges.
The issue was reported to the GNU Inetutils security team following its discovery.
The advisory, identified as VULN-TELNETD-SLC-2025 and released on March 13, 2026, is issued in the public interest to help defenders assess exposure and apply mitigations, in line with responsible disclosure practices. Tracked as CVE-2026-32746, the vulnerability is rated critical with a CVSS 3.1 score of 9.8. It is classified under CWE-120, which refers to a buffer copy without proper bounds checking, commonly known as a classic buffer overflow. The issue affects GNU InetUtils telnetd in all versions up to and including 2.7.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
