Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-24061 — CVE-2026-24061-PoC | Kitploit
Tools/GitHubGitHub/harygovind/cve-2026-24061
Vulnerability AnalysisExploitationWeb Application ExploitationNetwork SecurityPenetration TestingAuthentication
GitHubharygovind/cve-2026-24061

CVE-2026-24061

CVE-2026-24061-PoC

View Repository
72 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-24061: GNU InetUtils telnetd Argument Injection

Overview

An argument injection vulnerability affects the GNU InetUtils Telnet daemon (telnetd). Insufficient sanitization of client-supplied environment variables during NEW_ENVIRON negotiation allows an attacker to inject command-line flags into the local login process, potentially resulting in authentication bypass.

Severity

  • Type: Argument Injection / Authentication Bypass
  • Attack Vector: Network
  • Privileges Required: None
  • Affected Component: telnetd → /usr/bin/login

Affected Versions

GNU InetUtils telnetd 1.9.3 – 2.7 (unpatched).

Vulnerability Mechanism

During session negotiation, telnetd honors the NEW_ENVIRON Telnet option, which lets a client pass environment variables such as USER to the server. The daemon then interpolates this value directly into the argument list used to invoke /usr/bin/login.

Because the value is not validated to contain only legal username characters, a client can supply a string beginning with a hyphen (-). Rather than being treated as a username, this is parsed by login as a command-line flag. Depending on the login implementation, this can enable behaviors such as skipping password authentication (e.g., via a -f "already authenticated" flag), leading to unauthorized access.

Proof of Concept

Set the USER environment variable to a value containing an option flag before connecting:

USER="-f root" telnet -a <target_ip>

If the target is vulnerable, login interprets -f root as an instruction to authenticate as root without a password, rather than treating -f root as a literal username.

Detection

Check installed package version:

Debian / Ubuntu:

dpkg -l | grep inetutils-telnetd

RHEL / CentOS:

rpm -qa | grep inetutils

Remediation

  • Upgrade to a patched release of GNU InetUtils where telnetd rejects or strips any USER value beginning with - before passing it to login.
  • Disable telnet entirely in favor of SSH where possible — Telnet transmits credentials and data in cleartext regardless of this issue.
  • If telnet must remain in use, restrict access via firewall rules / VPN and monitor authentication logs for anomalous login flag usage.
Download Tool