Executive brief
A security vulnerability exists in the Altice Labs GR140DG fibre router, a device commonly used to provide internet services to SFR France customers. An attacker with valid login credentials can exploit a diagnostic tool to take full control of the router. This allows for the theft of sensitive data, modification of device settings, or the complete disruption of internet service for the household.
Technical details
An OS command injection vulnerability exists in the traceroute diagnostic handler within the /bin/httpd_clientside binary. The root cause is the improper neutralization of special elements in the 'destAddr' parameter before it is passed to a system() call. While the application performs basic character filtering via URIStringValidation(), it fails to block shell metacharacters used for command substitution. An authenticated attacker can leverage this to execute arbitrary shell commands with root privileges (uid=0). The vulnerability is addressed in firmware version 3GN8020803R0B.
Affected products
- Altice Labs / SFR France GR140DG Fibre Router 3GN8020801R13, 3GN8020802R0A, 3GN8020803R0A
Timeline
- 2026-01-08: other: Vulnerability discovered
- 2026-01-15: other: Vendor notified
- 2026-05-04: disclosed: Public disclosure
- 2026-05-05: advisory: CVE published