Internet security watchdog Shadowserver tracks nearly 800,000 IP addresses with Telnet fingerprints amid ongoing attacks exploiting a critical authentication bypass vulnerability in the GNU InetUtils telnetd server. The security flaw (CVE-2026-24061) already has a proof-of-concept exploit, impacts GNU InetUtils versions 1.9.3 (released in 2015) through 2.7, and was patched in version 2.8 (released on January 20). "The telnetd server invokes /usr/bin/login (normally running as root) passing the value of the USER environment variable received from the client as the last parameter," explained open-source contributor Simon Josefsson, who reported it. "If the client supply a carefully crafted USER environment value being the string "-f root", and passes the telnet(1) -a or --login parameter to send this USER environment to the server, the client will be automatically logged in as root bypassing normal authentication processes." Today, Shadowserver said that it's tracking nearly 800,000 IP addresses with Telnet fingerprints, over 380,000 from Asia, almost 170,000 from South America, and just over 100,000 from Europe. However, there is no information regarding how many of these devices have been secured against CVE-2026-24061 attacks. "We are ~800K telnet instances exposed globally - naturally, they should not be. [..] Telnet should not be publicly exposed, but often is especially on legacy iot devices," said Shadowserver Foundation CEO Piotr Kijewski. GNU InetUtils is a collectio...
Nearly 800,000 Telnet servers exposed to remote attacks
BleepingComputer
·Sergiu Gatlan
·Published Jan 26, 2026
·Updated
Affected Software
1 affected component
GNU InetUtils>=1.9.3<2.7
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses nearly 800,000 Telnet servers that are exposed to remote attacks due to a critical vulnerability in the GNU InetUtils telnetd server.
2
What security implications are discussed?
The article highlights the risks associated with an authentication bypass vulnerability which allows attackers to exploit Telnet servers.
3
What products or software are affected?
The affected software is the GNU InetUtils telnetd server, specifically versions between 1.9.3 and 2.7.
4
Who is tracking these exposed servers?
The Internet security watchdog Shadowserver is tracking the nearly 800,000 IP addresses with Telnet fingerprints.
5
What type of attacks are being carried out against these servers?
The attacks are exploiting a critical vulnerability that allows unauthorized access to the exposed Telnet servers.