8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
The ping diagnostic handler in /bin/httpd_clientside for ALTICE LABS / SFR France GR140DG and GR140IG fibre CPE/Router/Gateway, inserts unsanitized user input into a system() call, allowing authenticated remote attackers to execute arbitrary commands as root via crafted destAddr parameters using shell command substitution.
AI Analysis
Remote command execution vulnerability in ALTICE LABS / SFR France GR140DG and GR140IG fibre CPE/Router/Gateway
Basic Information
ID
CVE-2026-31195
Source
mitre
Published
May 5, 2026 at 00:00
Modified
May 6, 2026 at 18:09
Affected Product
Vendor
ALTICE LABS / SFR France
Product
GR140DG, GR140IG
Version
n/a
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
ALTICE LABS / SFR France
Product
GR140DG, GR140IG
Version
n/a