← Vulnerability feed

Vulnerability record · CVE-2007-0882 · published 12 February 2007

CVE-2007-0882: Solaris telnet daemon argument injection bypasses authentication

Oracle · Solaris

The telnet daemon (in.telnetd) in Solaris 10 and 11 mishandles certain client-supplied "-f" sequences, passing them to the login program as a request to skip authentication. A remote attacker can therefore log into certain accounts, including the bin account, without valid credentials.

10.0 CVSS 2.0 High EPSS 98% · top 0.1% CWE-88 · Argument injection
10.0CVSS 2.0 base score
98%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
38References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 2.0 base score is 10.0 with network reachability, no authentication, and complete confidentiality, integrity and availability impact, and EPSS is 0.98.

What it is

The telnet daemon (in.telnetd) in Solaris 10 and 11 mishandles certain client-supplied "-f" sequences, passing them to the login program as a request to skip authentication. A remote attacker can therefore log into certain accounts, including the bin account, without valid credentials.

Impact

An unauthenticated remote attacker gains login access to affected accounts on the target host, as demonstrated against the bin account. This yields a foothold on the system that can be used for further compromise.

Attack surface

Reachable over the network through the telnet service (AV:N, no authentication required, low complexity). No user interaction is needed; the attacker only needs to send crafted telnet input to the daemon.

Exploitation

Public exploit references exist (Exploit-tagged advisories and mailing list posts), and EPSS is very high at 0.98 (99.9th percentile). The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded here.

What to do

  • Apply the Oracle/Sun Solaris patch for the telnet daemon (Sun alert 102802) as the first action.
  • Disable the telnet service (in.telnetd) and use SSH instead where possible.
  • Restrict network access to TCP port 23 to trusted management hosts only.
  • Audit and disable unused accounts such as bin that could be targeted by the authentication bypass.
  • Monitor for and remove any unauthorized accounts or login sessions created through the telnet service.

Detection

  • Inspect telnet daemon logs and system auth logs for successful logins to accounts like bin without prior authentication.
  • Search for telnet connections containing "-f" sequences in client input or unusual telnet negotiation traffic.
  • Alert on interactive logins to service accounts (bin, daemon, sys) that should never have shell access.
  • Review process and session records for shells spawned from in.telnetd on Solaris 10/11 hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://erratasec.blogspot.com/2007/02/trivial-remote-solaris-0day-disable.html ExploitThird Party Advisory
http://isc.sans.org/diary.html?storyid=2220 ExploitThird Party Advisory
http://osvdb.org/31881 Broken Link
http://seclists.org/fulldisclosure/2007/Feb/0217.html Mailing ListThird Party Advisory
http://secunia.com/advisories/24120 Broken LinkVendor Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102802-1 Broken Link
http://www.kb.cert.org/vuls/id/881872 Third Party AdvisoryUS Government Resource
http://www.securityfocus.com/archive/1/459831/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/459843/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/459855/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/459980/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/460086/100/100/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/460103/100/100/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/22512 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1017625 Broken LinkThird Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA07-059A.html Broken LinkThird Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2007/0560 Broken LinkVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/32434 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2202 Broken Link
http://erratasec.blogspot.com/2007/02/trivial-remote-solaris-0day-disable.html ExploitThird Party Advisory
http://isc.sans.org/diary.html?storyid=2220 ExploitThird Party Advisory
http://osvdb.org/31881 Broken Link
http://seclists.org/fulldisclosure/2007/Feb/0217.html Mailing ListThird Party Advisory
http://secunia.com/advisories/24120 Broken LinkVendor Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102802-1 Broken Link
http://www.kb.cert.org/vuls/id/881872 Third Party AdvisoryUS Government Resource
http://www.securityfocus.com/archive/1/459831/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/459843/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/459855/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/459980/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/460086/100/100/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/460103/100/100/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/22512 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1017625 Broken LinkThird Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA07-059A.html Broken LinkThird Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2007/0560 Broken LinkVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/32434 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2202 Broken Link

Track CVE-2007-0882 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-14871Oracle Solaris PAM out-of-bounds write allows remote unauthenticated takeoverOracle Solaris 10 and 11 contain an out-of-bounds write (CWE-787) in the Pluggable Authentication Module component, reachable over the network withou…KEVEPSS 80%analysed8.8CVE-2019-3010Oracle Solaris XScreenSaver local privilege escalationA flaw in the XScreenSaver component of Oracle Solaris 11 allows a low-privileged user with a local logon to escalate privileges and take over the sy…KEVEPSS 13%analysed8.8CVE-2015-4495Firefox PDF reader same-origin bypass allows file read and privilege gainThe PDF reader in Mozilla Firefox (before 39.0.3), Firefox ESR 38.x (before 38.1.1), and Firefox OS (before 2.2) fails to properly validate origin, l…KEVEPSS 69%analysed7.8CVE-2008-2992Adobe Acrobat and Reader util.printf Stack Buffer OverflowAdobe Acrobat and Reader 8.1.2 and earlier contain a stack-based buffer overflow reachable through the util.printf JavaScript function when it is pas…KEVEPSS 98%analysed5.5CVE-2016-3718ImageMagick HTTP/FTP coders allow server-side request forgery via crafted imageImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 mishandles the HTTP and FTP coders, letting a crafted image trigger server-side request forgery. A…KEVEPSS 77%analysed5.5CVE-2016-3715ImageMagick EPHEMERAL coder allows arbitrary file deletionThe EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 lets a crafted image cause deletion of arbitrary files. This is part of the…KEVEPSS 75%analysed10.0CVE-2026-46978Oracle solaris improper access control vulnerabilityVulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon). The supported version that is affected is 11…EPSS 0.43%10.0CVE-2017-3623Oracle solaris vulnerabilityVulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel RPC). For supported versions that are affected see …EPSS 22%

Source: NIST National Vulnerability Database (record CVE-2007-0882), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.