CyberRota Analysis
Uzaktan istismar edilebilir olabilir.
CVE
CVE-2026-31196
Severity
HIGH
CVSS
8.8
EPSS
0.23%
Original NVD Description
The traceroute diagnostic handler in /bin/httpd_clientside for ALTICE LABS / SFR France GR140DG and GR140IG fibre CPE/Router/Gateway, inserts unsanitized user input into a system() call, allowing authenticated remote attackers to execute arbitrary commands as root via crafted destAddr parameters using shell command substitution.