CVE-2026-24061
9.5 CISA KEVGNU · InetUtils
GNU InetUtils telnetd allows unauthenticated remote attackers to bypass authentication by injecting a "-f root" value into the USER environment variable.
Executive summary
This critical vulnerability in GNU InetUtils telnetd allows unauthenticated attackers to bypass authentication, and it is currently being actively exploited in the wild.
Vulnerability
This is an argument injection vulnerability (CWE-88) occurring in the telnetd component. It allows an unauthenticated remote attacker to gain unauthorized access by manipulating the USER environment variable to force authentication as the root user.
Business impact
Successful exploitation grants an attacker complete, unauthenticated control over the affected system, resulting in total compromise of confidentiality, integrity, and availability. With a CVSS score of 9.5, this flaw represents an extreme risk to business operations, as it can lead to full server takeover, data exfiltration, and the deployment of persistent threats within the network environment.
Remediation
Immediate Action: Update to the latest version of GNU InetUtils as provided by your distribution vendor, or apply the upstream patches identified in the GNU InetUtils repository.
Proactive Monitoring: Monitor system logs for unusual telnet connections or authentication attempts involving the root user from unexpected IP addresses.
Compensating Controls: Disable the vulnerable telnet service immediately in favor of secure alternatives like SSH. If telnet is required, implement strict network segmentation or use a Web Application Firewall or Intrusion Prevention System to block traffic containing the malicious "-f root" argument string.
Exploitation status
Public Exploit Available: Yes, a Metasploit module and an ExploitDB entry exist.
Analyst recommendation
The extreme severity of this vulnerability, combined with the evidence of active exploitation in the wild, necessitates immediate remediation. Administrators must prioritize patching or disabling the vulnerable telnetd service across all affected systems. Given the critical nature of this flaw, failure to act will likely result in the total compromise of your infrastructure by threat actors utilizing the widely available public exploits.
More GNU CVEs
History
- Disclosed CVE record published
- Published in the daily brief critical section
- Published in the daily brief critical section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Analyst report written