GNU InetUtils Telnetd Remote Authentication Bypass Vulnerability (CVE-2026-24061) Notice

GNU InetUtils Telnetd Remote Authentication Bypass Vulnerability (CVE-2026-24061) Notice

janeiro 23, 2026 | NSFOCUS

Overview

Recently, NSFOCUS CERT detected that GNU issued a security bulletin to fix the GNU InetUtils Telnetd remote authentication bypass vulnerability (CVE-2026-24061); Since the telnetd process does not effectively verify the USER environment variable value passed in from the client when calling /usr/bin/login, an unauthenticated attacker can construct a specially crafted USER environment variable value through the client and send it to the server using the -a or –login parameters of telnet(1), thereby bypassing normal authentication and logging into the target host with root privileges. The CVSS score is 9.8. At present, the vulnerability details and PoC have been made public. Relevant users are requested to take measures to protect themselves as soon as possible.

GNU InetUtils is a set of core network tool suites developed by the GNU project, which includes the implementation of common network commands such as ftp, ping, and telnet. It is widely used for network communication and management of Linux/Unix systems. GNU InetUtils telnetd is the telnet server daemon in the GNU InetUtils suite, which is used to implement the server-side functions of the TELNET protocol.

Reference link: https://lists.gnu.org/archive/html/bug-inetutils/2026-01/msg00004.html

Scope of Impact

Affected versions

  • 1.9.3 <= GNU Inetutils <= 2.7

Note: Several Linux distributions such as Debian/Ubuntu/Kali Linux/Trisquel are known to be affected.

Vulnerability Detection

Manual check

Relevant users can determine whether the host has enabled the telnetd service and use the following command to view the version of telnetd:

apt show telnetd | grep -E “Source”
/usr/sbin/telnetd –version

If the current version is within the affected range, there may be a security risk.

Risk Investigation of Exposure Surface

Cloud detection

NSFOCUS External Attack Surface Management Service (EASM) supports Internet asset troubleshooting of telnetd service risks. It has helped service customer groups complete exposure surface troubleshooting and conduct vulnerability warnings and closed-loop disposal in a timely manner before threats occur. Interested customers can arrange detailed consultation and communication by contacting their local regional colleagues at NSFOCUS or sending an email to rs@nsfocus.com.

Tool troubleshooting

The NSFOCUS Automated Penetration Testing Tool (EZ) supports telnetd service identification and can be scanned using the servicescan2 module. (Note: For the enterprise version, please contact NSFOCUS sales staff to obtain it)

Mitigation

Official update

At present, the official security patch has been released to fix this vulnerability. Affected users are requested to install updates as soon as possible for protection.

Download link:

https://codeberg.org/inetutils/inetutils/commit/fd702c02497b2f398e739e3119bed0b23dd7aa7b

https://codeberg.org/inetutils/inetutils/commit/ccba9f748aa8d50a38d7748e2e60362edd6a32cc

Other protective measures

If the relevant users are temporarily unable to perform update operations, the following measures can also be used for temporary protection:

1. Since the telnet protocol is transmitted in plain text, it is recommended to disable the telnetd service and replace it with the sshd service.

2. Configure InetUtils telnetd to use the login tool with a custom address and disable the -f parameter.

Statement

This advisory is only used to describe a potential risk. NSFOCUS does not provide any commitment or promise on this advisory. NSFOCUS and the author will not bear any liability for any direct and/or indirect consequences and losses caused by transmitting and/or using this advisory. NSFOCUS reserves all the rights to modify and interpret this advisory. Please include this statement paragraph when reproducing or transferring this advisory. Do not modify this advisory, add/delete any information to/from it, or use this advisory for commercial purposes without permission from NSFOCUS.

About NSFOCUS

NSFOCUS, a pioneering leader in cybersecurity, is dedicated to safeguarding telecommunications, Internet service providers, hosting providers, and enterprises from sophisticated cyberattacks.

Founded in 2000, NSFOCUS operates globally with over 4000 employees at two headquarters in Beijing, China, and Santa Clara, CA, USA, and over 50 offices worldwide. It has a proven track record of protecting over 25% of the Fortune Global 500 companies, including four of the five largest banks and six of the world’s top ten telecommunications companies.

Leveraging technical prowess and innovation, NSFOCUS delivers a comprehensive suite of security solutions, including the Intelligent Security Operations Platform (ISOP) for modern SOC, DDoS Protection, Continuous Threat Exposure Management (CTEM) Service and Web Application and API Protection (WAAP). All the solutions and services are augmented by the Security Large Language Model (SecLLM), ML, patented algorithms and other cutting-edge research achievements developed by NSFOCUS.