CVE-2026-24061

9.5 CISA KEV

GNU · InetUtils

GNU InetUtils telnetd allows unauthenticated remote attackers to bypass authentication by injecting a "-f root" value into the USER environment variable.

Executive summary

This critical vulnerability in GNU InetUtils telnetd allows unauthenticated attackers to bypass authentication, and it is currently being actively exploited in the wild.

Vulnerability

This is an argument injection vulnerability (CWE-88) occurring in the telnetd component. It allows an unauthenticated remote attacker to gain unauthorized access by manipulating the USER environment variable to force authentication as the root user.

Business impact

Successful exploitation grants an attacker complete, unauthenticated control over the affected system, resulting in total compromise of confidentiality, integrity, and availability. With a CVSS score of 9.5, this flaw represents an extreme risk to business operations, as it can lead to full server takeover, data exfiltration, and the deployment of persistent threats within the network environment.

Remediation

Immediate Action: Update to the latest version of GNU InetUtils as provided by your distribution vendor, or apply the upstream patches identified in the GNU InetUtils repository.

Proactive Monitoring: Monitor system logs for unusual telnet connections or authentication attempts involving the root user from unexpected IP addresses.

Compensating Controls: Disable the vulnerable telnet service immediately in favor of secure alternatives like SSH. If telnet is required, implement strict network segmentation or use a Web Application Firewall or Intrusion Prevention System to block traffic containing the malicious "-f root" argument string.

Exploitation status

Public Exploit Available: Yes, a Metasploit module and an ExploitDB entry exist.

Analyst recommendation

The extreme severity of this vulnerability, combined with the evidence of active exploitation in the wild, necessitates immediate remediation. Administrators must prioritize patching or disabling the vulnerable telnetd service across all affected systems. Given the critical nature of this flaw, failure to act will likely result in the total compromise of your infrastructure by threat actors utilizing the widely available public exploits.

More GNU CVEs

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Published in the daily brief critical section
  4. Published in the daily brief kev section
  5. Published in the daily brief kev section
  6. Published in the daily brief kev section
  7. Published in the daily brief kev section
  8. Published in the daily brief kev section
  9. Published in the daily brief kev section
  10. Published in the daily brief kev section
  11. Published in the daily brief kev section
  12. Published in the daily brief kev section
  13. Published in the daily brief kev section
  14. Published in the daily brief kev section
  15. Published in the daily brief kev section
  16. Published in the daily brief kev section
  17. Published in the daily brief kev section
  18. Published in the daily brief kev section
  19. Published in the daily brief kev section
  20. Published in the daily brief kev section
  21. Published in the daily brief kev section
  22. Published in the daily brief kev section
  23. Published in the daily brief kev section
  24. Analyst report written

Sources