2026-01-20 20:59:08
GNU InetUtils Security Advisory: remote authentication by-pass in telnetd
π #telnet
GNU InetUtils Security Advisory: remote authentication by-pass in telnetd
π #telnet
2026-01-14: Il giorno in cui telnet morì
Il 14 gennaio 2026, il traffico #telnet globale osservato dai sensori di GreyNoise Γ¨ crollato. Una riduzione sostenuta del 59%, diciotto ASN completamente silenziosi e cinque paesi completamente scomparsi dai nostri dati. Sei giorni dopo, la CVE-2026-24061 Γ¨ scomparsa. La coincidenza Γ¨ una delle possibili spiegazioni.
π― Nearly 800,000 #Telnet servers potentially affected worldwide running vulnerable GNU inet utils implementations
π
Bug existed since 2015 code changes, finally patched January 20, 2026 in version 2.8
π§ The flaw stems from missing input sanitization: USER environment variable from network is passed unsanitized to login command, allowing flag injection
π¨ Critical #Telnet Authentication Bypass Vulnerability Discovered #CVE202624061 #cybersecurity #infosec