logo

Ancient telnet bug happily hands out root to attackers

ID: 15ff4247-abd1-5589-befc-9e43c47caeee

STIX ID: report--15ff4247-abd1-5589-befc-9e43c47caeee

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-01-22

Date Updated: 2026-04-26

Author: Connor Jones

...
...

A critical authentication-bypass bug (CVE-2026-24061, CVSS 9.8) in GNU InetUtils telnetd—introduced in 2015—allows remote attackers to obtain root by passing a crafted USER environment value (e.g., '-f root') combined with telnet's -a/--login option; exploitation is trivial and active scanning/exploit attempts were observed, prompting advisories to patch or decommission telnetd and restrict access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.