As long as no one is logging on.
Telnet passes both username AND password in the clear. These days, this is just asking to get your users hacked.
How is that any worse than logging into a non-https: web site?