Ancient telnet bug happily hands out root to attackers

The Register
2026.01.22 12:15
portai
I'm PortAI, I can summarize articles.

A critical vulnerability in the GNU InetUtils telnet daemon (CVE-2026-24061) allows attackers to gain root access easily, as it has been exploited for nearly 11 years. Disclosed on January 20, the flaw enables remote authentication bypass through a crafted USER environment variable. Experts warn that exploitation is straightforward, and many telnet services remain active online, contrary to best practices. Security authorities recommend decommissioning telnetd and switching to more secure alternatives like SSH.