logo

Critical Telnet Server Flaw Exposes Forgotten Attack Surface

ID: 009b1f4f-4aaa-549f-be0e-f0fb043a0c91

STIX ID: report--009b1f4f-4aaa-549f-be0e-f0fb043a0c91

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-01-27

Date Updated: 2026-04-21

Author: Rob Wright

...
...

A critical authentication bypass in GNU InetUtils telnetd (CVE-2026-24061) — introduced in 2015 and fixed in InetUtils 2.8 — allows attackers to bypass authentication (via argument injection using an "-f root" USER value) and potentially gain full control of affected devices; researchers warn the flaw is easy to exploit and threat actors are already targeting exposed Telnet servers, with estimations of roughly 800,000 Telnet instances publicly reachable, particularly on legacy and IoT devices. The report urges immediate patching or disabling of telnetd, network access restrictions to Telnet, segmentation of high-risk devices, and vendor remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.