Home
CRITICAL: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unknown
1.9.3 (custom)
affected
Description
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
Problem types
CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Product status
1.9.3 (custom)
References
www.openwall.com/lists/oss-security/2026/01/20/2
www.openwall.com/lists/oss-security/2026/01/20/8
www.gnu.org/software/inetutils/