telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
This vulnerability is actively exploited in the wild. Immediate patching is strongly recommended.
Due Date: Feb 16, 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
How easy to exploit
Severity of consequences
Likelihood of exploitation in next 30 days