CVE-2026-24714
7.5NETGEAR · Multiple Products
Certain end of service NETGEAR products contain a TelnetEnable feature that allows an unauthenticated attacker to remotely activate the telnet service via a specialized magic packet.
Executive summary
A vulnerability in legacy NETGEAR devices permits unauthorized activation of the telnet service, exposing affected hardware to potential remote command execution.
Vulnerability
The flaw stems from the inclusion of undocumented TelnetEnable functionality, which allows an unauthenticated attacker to enable remote management services on the device by sending a crafted magic packet.
Business impact
The ability for an unauthorized party to enable telnet services on network infrastructure presents a significant risk of remote administrative access and complete system compromise. Given the CVSS score of 7.5, this high-severity issue could lead to unauthorized configuration changes, data interception, or the use of compromised hardware to facilitate further attacks within the internal network.
Remediation
Immediate Action: Since these products are end of service, the most secure action is to retire and replace the affected hardware with currently supported devices.
Proactive Monitoring: Monitor network traffic for unusual telnet connection requests or attempts to utilize undocumented management protocols on your network segments.
Compensating Controls: Implement strict network segmentation and utilize firewalls to block all inbound traffic to management ports, including port 23, from untrusted sources.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability highlights the severe security risks associated with maintaining end of service hardware that contains undocumented management features. Organizations using legacy NETGEAR equipment should prioritize the decommissioning of these devices, as they likely lack modern security controls and official patches, making them permanent targets for attackers.