Oh, that's neat. For those who want to play with this, Denon documents it in the manuals and downloads section of their site. Go here [1], find the page for your receiver, and look for the document with "protocol" in its name.
If they don't have it listed for your receiver, a couple I know have them are AVR-1913 (Rev 8.5.0 of the protocol document) and AVR-X4000 (Rev 10.0.3).
I tried it and it worked.
echo -ne MVUP\\r | nc denon 23
increased the volume by one notch.
The remote app on my phone is able to get a listing showing my favorite stations in the internet radio app of the receiver, and I didn't see offhand how that is done via the telnet interface, so I watched via tcpdump while the app did it, after some difficulty [2].
It turns out that the remote app for my AVR-1913 is not using the telnet interface. It's doing HTTP POST to the receiver's web server. All the ones I saw were to /goform/AppCommand.xml. What it posts is some XML with one or more commands. For example, it posts this periodically to get information:
<?xml version="1.0" encoding="utf-8"?>
<tx>
<cmd id="1">GetAllZonePowerStatus</cmd>
<cmd id="1">GetVolumeLevel</cmd>
<cmd id="1">GetMuteStatus</cmd>
<cmd id="1">GetSourceStatus</cmd>
</tx>
The response is XML with the root element being <rx>, then one or more <cmd> elements. The number of <cmd> elements in the response seems to be the same as the number in the request, and they contain the response for the corresponding command.
Here's what is coming back for the <tx> shown above (formatted a bit nicer):
<?xml version="1.0" encoding="utf-8" ?>
<rx>
<cmd>
<zone1>ON</zone1>
<zone2>OFF</zone2>
</cmd>
<cmd>
<volume>-40.0</volume>
<disptype>RELATIVE</disptype>
<dispvalue>-40.0dB</dispvalue>
</cmd>
<cmd>
<mute>off</mute>
</cmd>
<cmd>
<source>SAT/CBL</source>
</cmd>
</rx>
I've only searched briefly, but so far not found any documentation for this.
[1] https://usa.denon.com/us/downloads/manuals-and-downloads
[2] I set my switch [3] to mirror the port the receiver is on to my Mac, but was not seeing anything with tcpdump on the Mac. Took me an embarrassingly long time to remember that if you don't explicitly specify the interface to monitor, it monitors them all but not in promiscuous mode, so you only see traffic to/from yourself.
[3] TP-Link SG-108E. I highly recommend this or the SG-105E or others in the family. They are unmanaged switches, but they do support port mirroring, some VLAN features, and some QOS features that you normally have to go to an expensive managed switch for. My 108E (8 port) was only $30. The only thing I don't like about it is that the status lights for the ports are in the back, above the connectors, rather than on the front.