Improper privilege management in Inetutils - GNU network utilities - CVE-2026-28372
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper handling of environment variables in telnetd when processing environment options with util-linux login systemd service credentials support. A remote attacker can pass crafted environment variables to escalate privileges.
Exploitation depends on util-linux login(1) support for systemd service credentials.
Affected software
LANTIME Operating System Firmware (LTOS)
How to mitigate CVE-2026-28372
LANTIME Operating System Firmware (LTOS) - update to 7.10.012