logo

How to find potentially vulnerable GNU inet-utils telnetd servers on your network

ID: 3f60c044-86b4-5d11-a7a1-808a15155f78

STIX ID: report--3f60c044-86b4-5d11-a7a1-808a15155f78

Feed Name: runZero Blog

Threat Score
90/100

Date Published: 2026-01-20

Date Updated: 2026-04-29

Author: Rob King

...
...

GNU inet-utils telnetd contains a critical authentication-bypass vulnerability (CVE-2026-24061, CVSS 9.8) in its handling of the $USER environment variable that can allow remote, unauthenticated attackers to gain any user's privileges including root. The issue affects inet-utils telnetd 1.9.3 and higher, currently has no patch, and the report recommends disabling telnet and enforcing network access controls; a runZero query is provided to help locate potentially vulnerable hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.