telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.345
EPSS Ranking 96.9%
CVSS Severity
CVSS v3 Score 9.8
Proposed Action
GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable.