logo

How to find potentially vulnerable GNU inet-utils telnetd servers on your network

ID: 9b5e0021-98ab-5962-9429-d9b78c7d3567

STIX ID: report--9b5e0021-98ab-5962-9429-d9b78c7d3567

Feed Name: runZero Blog

Threat Score
75/100

Date Published: 2026-01-20

Date Updated: 2026-04-29

Author: Rob King

...
...

A recently reported authentication-bypass vulnerability in GNU inet-utils telnetd allows a crafted $USER environment variable to bypass authentication and grant remote, unauthenticated access to any user account (including root). Affects inet-utils telnetd versions 1.9.3 and higher; no CVE or patch is available yet, so the guidance is to disable telnet where possible and tighten network access controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.