Definition · Open Ports & Services

What is Telnet?

Telnet provides an interactive command-line session to a remote host over TCP port 23. It predates any expectation of network confidentiality: everything, including the password typed at the login prompt, crosses the network unencrypted. SSH replaced it for exactly this reason, and finding telnet on a public address in the present day is close to an automatic finding.

Where it still turns up

Telnet survives on equipment rather than servers — network switches and routers, KVM and out-of-band management cards, industrial and building control systems, VoIP hardware, cameras and other embedded devices. Often the management web interface was secured or moved and the telnet daemon simply stayed enabled, because disabling it was never part of anyone’s checklist.

That population overlaps heavily with default credentials, since the same devices ship with documented factory passwords. Internet-wide scanning for telnet with default or trivial credentials is a long-established technique for assembling botnets from consumer and embedded devices, and it requires no exploit — just a login.

What to do about it

Disable the service. On a device where a remote management path is genuinely needed, use SSH if the firmware supports it, and reach the device through a VPN gateway or a management network rather than the public internet. Where firmware is too old to offer an encrypted option, that is an argument for network segmentation and, eventually, replacement.

Externally, an open port 23 is straightforward to detect: port scanning finds it and the login banner usually identifies the device and firmware through service fingerprinting.

See FTP for the plaintext file transfer equivalent, and SMB and RDP for other services that should not be published. Exposed telnet is a textbook security misconfiguration and a candidate for attack surface reduction.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.