AbsoluteTelnet Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in AbsoluteTelnet version 11.24. This issue allows local attackers to crash the application by manipulating the DialUp connection and license name fields. Exploitation involves generating a 1000-character payload, which can be pasted into these specific input fields, causing the application to crash and terminate unexpectedly.

Impact

Exploitation of this vulnerability leads to a crash of the AbsoluteTelnet application, causing an unexpected termination of the program.

Reproduction

To reproduce this vulnerability, download and install AbsoluteTelnet version 11.24. After installation, a Python script can be used to create a text file containing a 1000-character payload. This file can then be used to populate the 'DialUp Connection' phone field, which will cause the application to crash. The same payload can be copied into the 'license name' field, which also triggers a crash.

Added: Jan 15, 2026, 4:54 PM
Updated: Jan 15, 2026, 4:54 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.6
remediation
0.0
relevance
2.1
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.