logo

Critical GNU InetUtils Vulnerability Allows Unauthenticated Root Access Via “-f root”

ID: 9ac66788-ee4a-5de7-b47c-247327c576db

STIX ID: report--9ac66788-ee4a-5de7-b47c-247327c576db

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-01-21

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical authentication-bypass flaw in GNU InetUtils' telnetd (introduced in version 1.9.3 and present through 2.7) allows unauthenticated remote attackers to gain immediate root by passing a crafted USER environment variable (such as "-f root") to /usr/bin/login; organizations are advised to disable telnetd, restrict access, or apply vendor patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.