logo

Hackers Exploiting telnetd Vulnerability for Root Access – Public PoC Released

ID: 6fe21af4-1d45-5b95-bf56-5f8b7f18bd6f

STIX ID: report--6fe21af4-1d45-5b95-bf56-5f8b7f18bd6f

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-01-24

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Active exploitation of CVE-2026-24061:** A critical authentication-bypass in GNU InetUtils telnetd (affecting versions 1.9.3–2.7) allows attackers to pass a crafted USER environment value (eg. "-f root") during Telnet negotiation to invoke /usr/bin/login and obtain a root shell; Grey Noise observed ~60 attempts from 18 IPs with follow-on activity including SSH key injection and delivery of a Python payload (apps.py) from http://67.220.95.16:8000.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.