Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Access
Overview
A serious vulnerability has been discovered in the GNU InetUtils telnet daemon (telnetd) that has existed for nearly 11 years. This flaw, identified as CVE-2026-24061, allows attackers to bypass authentication remotely and gain root access to affected systems. It impacts all versions of GNU InetUtils from 1.9.3 to 2.7. Given its high CVSS score of 9.8, this vulnerability poses a significant risk to organizations still using these versions. Users and administrators should prioritize addressing this issue to prevent unauthorized access to their systems.
Key Takeaways
- Affected Systems: GNU InetUtils telnet daemon (telnetd), all versions from 1.9.3 to 2.7
- Action Required: Users should upgrade to the latest version of GNU InetUtils that addresses this vulnerability.
- Timeline: Disclosed on [specific date not provided]
Original Article Summary
A critical security flaw has been disclosed in the GNU InetUtils telnet daemon (telnetd) that went unnoticed for nearly 11 years. The vulnerability, tracked as CVE-2026-24061, is rated 9.8 out of 10.0 on the CVSS scoring system. It affects all versions of GNU InetUtils from version 1.9.3 up to and including version 2.7. "Telnetd in GNU Inetutils through 2.7 allows remote authentication bypass
Impact
GNU InetUtils telnet daemon (telnetd), all versions from 1.9.3 to 2.7
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Disclosed on [specific date not provided]
Remediation
Users should upgrade to the latest version of GNU InetUtils that addresses this vulnerability. Specific patch numbers or versions were not mentioned, so it's crucial to consult official sources for the latest updates.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Vulnerability, Critical.