Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-24061

Quick assessment

Affected
GNU Inetutils
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GNU Inetutils是美国GNU社区的一组常见的网络程序。 GNU Inetutils 2.7及之前版本存在参数注入漏洞,该漏洞源于通过USER环境变量绕过远程身份验证。

CVSS 9.8 · Critical KEV EPSS 98.98% · P100

Public Exploits 2

ExploitDB · 1 EDB-52524 [local]

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
GNU Inetutils 1.9.3≤ 2.7 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-24061

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
参数注入或修改
Source: CVE Program / CVE List V5
Vulnerability Title
GNU Inetutils 参数注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GNU Inetutils是美国GNU社区的一组常见的网络程序。 GNU Inetutils 2.7及之前版本存在参数注入漏洞,该漏洞源于通过USER环境变量绕过远程身份验证。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
GNU Inetutils 1.9.3 ~ 2.7 -

II. Public POCs for CVE-2026-24061

# POC Description Source Link Shenlong Link
1 None https://github.com/Threekiii/Awesome-POC/blob/master/%E6%93%8D%E4%BD%9C%E7%B3%BB%E7%BB%9F%E6%BC%8F%E6%B4%9E/GNU%20InetUtils%20telnetd%20%E5%8F%82%E6%95%B0%E6%B3%A8%E5%85%A5%E8%AE%A4%E8%AF%81%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E%20CVE-2026-24061.md POC Details
2 GNU Inetutils telnetd through 2.7 contains an authentication bypass caused by setting the USER environment variable to \"-f root\", letting remote attackers bypass authentication, exploit requires remote access to telnetd service. https://github.com/projectdiscovery/nuclei-templates/blob/main/code/cves/2026/CVE-2026-24061.yaml POC Details
3 https://github.com/vulhub/vulhub/blob/master/inetutils/CVE-2026-24061/README.md POC Details
4 A small docker lab to play with cve-2026-24061, the inetutils-telnetd authentication bypass. https://github.com/leonjza/inetutils-telnetd-auth-bypass POC Details
5 Bypass d’authentification Telnet menant à un accès root https://github.com/duy-31/CVE-2026-24061---telnetd POC Details
6 CVE-2026-24061 Batch Scanning Tool https://github.com/TryA9ain/CVE-2026-24061 POC Details
7 基于cve-2026-24061 telnet远程认证绕过漏洞的批量检测利用工具 https://github.com/parameciumzhang/Tell-Me-Root POC Details
8 None https://github.com/Chocapikk/CVE-2026-24061 POC Details
9 None https://github.com/JayGLXR/CVE-2026-24061-POC POC Details
10 GNU InetUtils telnetd 远程身份认证绕过漏洞(CVE-2026-24061),此漏洞主要影响 telnetd 在调用系统 /usr/bin/login 程序时,未对从客户端 USER 环境变量传入的用户名做过滤,直接拼接到 login 命令行。未经授权的远程攻击者可利用该缺陷,在无需任何口令的情况下直接获取目标主机的 root shell。 https://github.com/yanxinwu946/CVE-2026-24061--telnetd POC Details
11 Exploitation of CVE-2026-24061 https://github.com/SafeBreach-Labs/CVE-2026-24061 POC Details
12 CVE-2026-24061 - Exploit https://github.com/h3athen/CVE-2026-24061 POC Details
13 None https://github.com/xuemian168/CVE-2026-24061 POC Details
14 CVE-2026-24061 漏洞检测工具 https://github.com/monstertsl/CVE-2026-24061 POC Details
15 CVE-2026-24061 环境 https://github.com/r00tuser111/CVE-2026-24061 POC Details
16 inetutils-telnetd Authentication Bypass - working https://github.com/balgan/CVE-2026-24061 POC Details
17 Proof of Concept: CVE-2026-24061 is a critical authentication bypass vulnerability in GNU inetutils-telnetd allowing unauthenticated remote attackers to gain instant root shell access via malicious NEW_ENVIRON telnet option exploitation. https://github.com/SystemVll/CVE-2026-24061 POC Details
18 None https://github.com/z3n70/CVE-2026-24061 POC Details
19 Nuclei template for CVE-2026-24061 https://github.com/Mr-Zapi/CVE-2026-24061 POC Details
20 GNU Inetutils telnetd Remote Authentication Bypass https://github.com/midox008/CVE-2026-24061 POC Details
21 None https://github.com/BrainBob/CVE-2026-24061 POC Details
22 None https://github.com/BrainBob/Telnet-TestVuln-CVE-2026-24061 POC Details
23 CVE-2026-24061's poc : a critical authentication bypass in telnetd leading to RCE as root Affects systems with telnetd versions containing the vulnerability from 2015 onwards. https://github.com/0p5cur/CVE-2026-24061-POC POC Details
24 Docker setup for CVE-2026-24061 https://github.com/shivam-bathla/CVE-2026-24061-setup POC Details
25 CVE-2026-24061 - GNU InetUtils Telnetd Remote Authentication Bypass https://github.com/madfxr/Twenty-Three-Scanner POC Details
26 CVE-2026-24061 - GNU InetUtils telnetd authentication bypass POC + Docker lab environment for testing https://github.com/Alter-N0X/CVE-2026-24061-POC POC Details
27 GNU telnetd service from GNU InetUtils authentication-bypass https://github.com/typeconfused/CVE-2026-24061 POC Details
28 CVE-2026-24061 https://github.com/Mefhika120/Ashwesker-CVE-2026-24061 POC Details
29 CVE-2026-24061 PoC https://github.com/infat0x/CVE-2026-24061 POC Details
30 None https://github.com/ms0x08-dev/CVE-2026-24061-POC POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-24061

请登录查看更多情报信息。

Mailing List Discussions for CVE-2026-24061 (1)

Security Blog Posts for CVE-2026-24061 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-24061

No comments yet


Leave a comment