CVE-2016-1888: Freebsd

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

The telnetd service in FreeBSD 9.3, 10.1, 10.2, 10.3, and 11.0 allows remote attackers to inject arguments to login and bypass authentication via vectors involving a "sequence of memory allocation failures."

Affected products

  • Freebsd Freebsd: version 9.3 only; version 10.1 only; version 10.2 only; version 10.3 only; version 11.0 only

Published 2017-02-15. Last modified 2026-06-17.