Auth Bypass/Privesc in Telnetd

Wowowow

If the client supply a carefully crafted USER environment value being
the string “-f root”, and passes the telnet(1) -a or --login parameter
to send this USER environment to the server, the client will be
automatically logged in as root bypassing normal authentication
processes.

It works as advertised.

1 Like