---
id: CVE-2021-47765
title: AbsoluteTelnet 11.24 - 'Username' Denial of Service (PoC)
summary: >-
  AbsoluteTelnet 11.24 contains a denial of service vulnerability that allows
  local attackers to crash the application by manipulating username and error
  report fields. Attackers can trigger the crash by inserting 1000 characters
  into the …
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cvssSource: cna
cwe:
  - CWE-787
vendor: Celestialsoftware
product: AbsoluteTelnet
affected:
  - AbsoluteTelnet 11.24
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-01-15T16:47:29.833009Z'
exploitAvailable: true
published: '2026-01-15'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:39.537Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2021-47765'
references:
  - url: 'https://www.exploit-db.com/exploits/50510'
    label: ExploitDB-50510
  - url: 'https://www.celestialsoftware.net/'
    label: Vendor Homepage
tags:
  - cve.org
  - exploit-available
epss: 0.00196
epssPercentile: 0.08433
ingestedAt: '2026-10-01T15:48:17.873Z'
---

## Overview

AbsoluteTelnet 11.24 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating username and error report fields. Attackers can trigger the crash by inserting 1000 characters into the username or email address fields, causing the application to become unresponsive.

## Affected

- `AbsoluteTelnet 11.24`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
