Junglewise Threat Intelligence

CVE-2026-31195: Altice Labs SFR France GR140DG OS command injection in ping handler

CVE-2026-31195 · Severity: high · CVSS 8.8 · Published 2026-05-05

Executive brief

A security vulnerability exists in the Altice Labs / SFR France GR140DG fibre router, a device commonly used to provide internet access to home and business customers. An attacker with access to the router's management interface can take complete control of the device by sending a specially crafted diagnostic request. This could allow an unauthorized party to monitor internet traffic, steal credentials, or disable the internet connection entirely.

Technical details

An OS command injection vulnerability exists in the ping diagnostic handler within the /bin/httpd_clientside binary of the ALTICE LABS / SFR France GR140DG router. The vulnerability is caused by the improper neutralization of the 'destAddr' parameter before it is passed to a system() call. While the application performs basic character filtering, it fails to block shell metacharacters used for command substitution. An authenticated attacker can exploit this by injecting shell commands into the destination address field, which are then executed with root privileges (uid=0). The issue is addressed in firmware version 3GN8020803R0B by implementing stricter hostname validation.

Affected products

  • ALTICE LABS / SFR France GR140DG Fibre Router 3GN8020801R13, 3GN8020802R0A, 3GN8020803R0A

Timeline

  • 2026-01-08: other: Vulnerability discovered
  • 2026-01-15: other: Vendor notified
  • 2026-05-04: advisory: Public disclosure by researcher
  • 2026-05-05: disclosed: CVE published

References

Related threats