Junglewise Threat Intelligence

CVE-2026-31196: Altice Labs SFR GR140DG OS command injection in traceroute handler

CVE-2026-31196 · Severity: high · CVSS 8.8 · Published 2026-05-05

Executive brief

A security vulnerability exists in the Altice Labs GR140DG fibre router, a device commonly used to provide internet services to SFR France customers. An attacker with valid login credentials can exploit a diagnostic tool to take full control of the router. This allows for the theft of sensitive data, modification of device settings, or the complete disruption of internet service for the household.

Technical details

An OS command injection vulnerability exists in the traceroute diagnostic handler within the /bin/httpd_clientside binary. The root cause is the improper neutralization of special elements in the 'destAddr' parameter before it is passed to a system() call. While the application performs basic character filtering via URIStringValidation(), it fails to block shell metacharacters used for command substitution. An authenticated attacker can leverage this to execute arbitrary shell commands with root privileges (uid=0). The vulnerability is addressed in firmware version 3GN8020803R0B.

Affected products

  • Altice Labs / SFR France GR140DG Fibre Router 3GN8020801R13, 3GN8020802R0A, 3GN8020803R0A

Timeline

  • 2026-01-08: other: Vulnerability discovered
  • 2026-01-15: other: Vendor notified
  • 2026-05-04: disclosed: Public disclosure
  • 2026-05-05: advisory: CVE published

References

Related threats