9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
AI Analysis
Remote authentication bypass vulnerability in telnetd via USER environment variable
Basic Information
ID
CVE-2026-24061
Source
mitre
Published
Jan 21, 2026 at 06:42
Modified
Jan 21, 2026 at 07:03
Affected Product
Vendor
GNU
Product
Inetutils
Version
1.9.3
Affected Versions
GNU Inetutils 1.9.3
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
GNU
Product
Inetutils
Version
1.9.3