Ancient telnet bug happily hands out root to attackers
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A critical vulnerability (CVE-2026-24061) in GNU InetUtils telnetd allows attackers to gain root access through a trivial authentication bypass. The bug, which went undetected for 11 years since May 2015, can be exploited by sending a crafted USER environment variable ('-f root') to bypass login authentication. Active exploitation attempts are already underway with 15 unique IPs detected in 24 hours. Security experts strongly recommend discontinuing telnetd entirely and migrating to SSH, as telnet is unencrypted and fundamentally insecure. Multiple national cybersecurity authorities have issued advisories urging immediate patching or decommissioning of telnet services.
13.7K Impressions1 Comment