Is busybox affected by CVE-2026-24061?

Post new topic   Reply to topic    DD-WRT Forum Index -> Generic Questions
Author Message
yoyoma2
DD-WRT User


Joined: 24 Sep 2016
Posts: 410

PostPosted: Sat Jan 31, 2026 21:37    Post subject: Is busybox affected by CVE-2026-24061? Reply with quote
Is busybox affected by CVE-2026-24061? In the comments someone is asking about busybox.

This video demonstrates how to login with telnet as root without a password prompt. I tried it against my dd-wrt and still got prompted for the password.
Sponsor
yoyoma2
DD-WRT User


Joined: 24 Sep 2016
Posts: 410

PostPosted: Fri Feb 06, 2026 18:33    Post subject: Reply with quote
BusyBox telnetd is not vulnerable to CVE-2026-24061 because it does not construct the login command using user-controlled placeholders. Instead, it invokes the login process using fixed arguments, which prevents argument injection and authentication bypass in this context. source

Thank you for your attention to this matter.
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 16813
Location: Texas, USA

PostPosted: Fri Feb 06, 2026 20:06    Post subject: Reply with quote
Moved to Generic (development). I couldn't find anything that pointed towards this vulnerability, just didn't respond until now. Source code for telnetd applet in busybox is not entirely the same nor does it use the same constructs as inetutils' telnetd as you noted.
_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
RSS feed for DD-WRT releases (2025)
RSS feed for DD-WRT releases (2024)
RSS feed for DD-WRT releases (2023)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Generic Questions All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum