Security Advisory

CVE-2026-31195

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-05 00:00:00
Last updated 2026-06-15 14:42:49
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

OS command injection vulnerability in the ping diagnostic handler in /bin/httpd_clientside in ALTICE LABS / SFR France GR140DG Fibre Router with firmware 3GN8020801R13, 3GN8020802R0A, or 3GN8020803R0A inserts unsanitized user input into a system() call, allowing authenticated remote attackers to execute arbitrary commands as root via crafted destAddr parameters using shell command substitution.