info: name: Linux Root Remote Login - Security Misconfiguration author: songyaeji severity: high description: Root account remote login via telnet or SSH is enabled, which poses a significant security risk. This template checks the root account access settings in `/etc/securetty` and `sshd_config`. reference: - https://book.hacktricks.xyz/linux-hardening/privilege-escalation classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score:9.8 cwe-id: CWE-306 metadata: verified:true max-request:2 os: linux tags: linux,ssh,root,misconfiguration,local