logo

Attackers Leveraging telnetd Exploit for Root Privileges After PoC Goes Public

ID: 7b41ff9e-79be-51b6-9da5-fe793ef0436f

STIX ID: report--7b41ff9e-79be-51b6-9da5-fe793ef0436f

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-01-24

Date Updated: 2026-04-22

Author: Divya

...
...

A critical authentication-bypass in GNU InetUtils telnetd (versions 1.9.3–2.7) allows attackers to obtain root access by supplying a crafted USER environment variable (e.g., “-f root”) combined with telnet login parameters; proof-of-concept code was published and patches issued January 20, 2026. Security sensors observed widespread exploitation attempts starting January 21, including 18 attacker IPs and 60 attempts against honeypots, network traffic exclusively over Telnet/TCP 23, IDS alerts indicating root access, and subsequent attempts to deploy a Python-based payload from 67.220.95.16:8000. Organizations are advised to audit exposed Telnet services, review authentication logs for suspicious root logins, and treat successful exploitations as full compromises requiring incident response and rebuilds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.