logo

GNU InetUtils Vulnerability Exploited via “-f root” to Achieve Full System Control

ID: e41869b5-398e-561f-9cd9-bc1b33cd6905

STIX ID: report--e41869b5-398e-561f-9cd9-bc1b33cd6905

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-01-21

Date Updated: 2026-04-22

Author: Divya

...
...

A critical authentication-bypass flaw in GNU InetUtils' telnetd (introduced in v1.9.3 and present through v2.7) allows remote, unauthenticated attackers to obtain an immediate root shell by injecting "-f root" into the USER environment variable; the report includes technical details, a PoC command, affected commits, and recommends disabling telnetd or applying patches (fd702c02, ccba9f748) and migrating to SSH.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.