CVE-2026-31196Patch

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OS command injection vulnerability in the traceroute diagnostic handler in /bin/httpd_clientside in ALTICE LABS / SFR France GR140DG Fibre Router with firmware 3GN8020801R13, 3GN8020802R0A, or 3GN8020803R0A inserts unsanitized user input into a system() call, allowing authenticated remote attackers to execute arbitrary commands as root via crafted destAddr parameters using shell command substitution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-25: 1Patch / Workaround · 2026-05-25: 1Technical Details · 2026-05-25: 105-25
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-31196 (CVSS 8.8) - Command injection in ALTICE LABS/SFR France GR140DG/GR140IG routers. Authenticated attackers can execute arbitrary commands as root via traceroute handler. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/PFnGAa34F3

    Post summary

    CVE‑2026‑31196 is a high‑severity command injection vulnerability in ALTICE LABS/SFR France routers that allows authenticated attackers to execute arbitrary commands as root via the traceroute handler; patch is urgently recommended.

    00000115
    30 followersView on X

Explore more