Cyber Resilience

CVE-2026-24714

High

Published: 30 January 2026

Published
30 January 2026
Modified
15 April 2026
KEV Added
Patch
CVSS Score v4 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score 0.0023 13.4th percentile
Risk Priority 55 floored blend · peak EPSS

Summary

CVE-2026-24714 is a high-severity Inclusion of Undocumented Features or Chicken Bits (CWE-1242) vulnerability in Jvn (inferred from references). Its CVSS base score is 8.7 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique External Remote Services (T1133); ranked at the 13.4th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability details

Some end of service NETGEAR products provide "TelnetEnable" functionality, which allows a magic packet to activate telnet service on the box.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

T1133 External Remote Services Persistence
Adversaries may leverage external-facing remote services to initially access and/or persist within a network.
T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Why these techniques?

Magic packet enables undocumented Telnet backdoor on public-facing network device (external remote service activation and public app exploitation).

Confidence: MEDIUM · MITRE ATT&CK Enterprise v19.0

Affected Assets

Jvn
inferred from references and description; NVD did not file a CPE for this CVE

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-1242

Requiring an inventory that accurately reflects the system forces documentation of all components, making inclusion of undocumented features or chicken bits harder to achieve without detection.

addresses: CWE-1242

Review and update processes include scrutiny of undocumented features or debug mechanisms provided by component manufacturers.

addresses: CWE-1242

Requires transparency and verification of delivered components, limiting undocumented features or debug hooks introduced upstream.

addresses: CWE-1242

Discourages undocumented features or chicken bits by demanding transparency and verification that only intended, documented behavior is present.

addresses: CWE-1242

Developing critical components internally avoids undocumented features and chicken bits present in vendor hardware or software.

addresses: CWE-1242

Requiring screened developers with proper access limits the introduction of undocumented features or debug 'chicken bits' that could be exploited later.

addresses: CWE-1242

Inspection can uncover undocumented features or chicken bits that result from tampering or malicious insertion.

References