Vulnerability record · CVE-2007-0882 · published 12 February 2007
CVE-2007-0882: Solaris telnet daemon argument injection bypasses authentication
Oracle · Solaris
The telnet daemon (in.telnetd) in Solaris 10 and 11 mishandles certain client-supplied "-f" sequences, passing them to the login program as a request to skip authentication. A remote attacker can therefore log into certain accounts, including the bin account, without valid credentials.
Description
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score is 10.0 with network reachability, no authentication, and complete confidentiality, integrity and availability impact, and EPSS is 0.98.
What it is
The telnet daemon (in.telnetd) in Solaris 10 and 11 mishandles certain client-supplied "-f" sequences, passing them to the login program as a request to skip authentication. A remote attacker can therefore log into certain accounts, including the bin account, without valid credentials.
Impact
An unauthenticated remote attacker gains login access to affected accounts on the target host, as demonstrated against the bin account. This yields a foothold on the system that can be used for further compromise.
Attack surface
Reachable over the network through the telnet service (AV:N, no authentication required, low complexity). No user interaction is needed; the attacker only needs to send crafted telnet input to the daemon.
Exploitation
Public exploit references exist (Exploit-tagged advisories and mailing list posts), and EPSS is very high at 0.98 (99.9th percentile). The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded here.
What to do
- Apply the Oracle/Sun Solaris patch for the telnet daemon (Sun alert 102802) as the first action.
- Disable the telnet service (in.telnetd) and use SSH instead where possible.
- Restrict network access to TCP port 23 to trusted management hosts only.
- Audit and disable unused accounts such as bin that could be targeted by the authentication bypass.
- Monitor for and remove any unauthorized accounts or login sessions created through the telnet service.
Detection
- Inspect telnet daemon logs and system auth logs for successful logins to accounts like bin without prior authentication.
- Search for telnet connections containing "-f" sequences in client input or unusual telnet negotiation traffic.
- Alert on interactive logins to service accounts (bin, daemon, sys) that should never have shell access.
- Review process and session records for shells spawned from in.telnetd on Solaris 10/11 hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-0882 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-0882), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.