HabrAugust 10, 2026🇷🇺Translated from Russian

Researchers Expose GPON Optical Network Eavesdropping via Modified ONU Devices at DEF CON

At DEF CON 34, researchers presented an attack technique called GPWN that exploits fundamental characteristics of GPON (Gigabit Passive Optical Network) infrastructure to eavesdrop on neighboring subscribers' downstream traffic.

The passive nature of these networks means that all clients connected to the same optical splitter receive identical data; separation occurs only at the Optical Network Unit (ONU) through software filtering of GEM frames carrying 12-bit port identifiers. Using approximately one hundred dollars' worth of hardware, the researchers modified commodity Realtek RTL960x SFP modules to override these filters.

They sequentially disabled multiple protective mechanisms: GEM port identifier reassignment, VLAN tagging enforcement, internal switch forwarding rules, and various checksum validations. The result was the ability to read traffic destined for as many as 128 other subscribers on the same splitter—an apparent hardware limit of consumer-grade ONUs.

Although most traffic is encrypted, the researchers showed that DNS queries remain visible and can indicate when a residence is unoccupied. In certain deployments, cellular base-station traffic and unencrypted SIP voice calls were also observable. Importantly, only downstream traffic could be intercepted; upstream traffic remained protected.

The presentation further examined the possibility of compromising the provider-side Optical Line Terminal (OLT). Analysis of the VSOL G100S OLT revealed multiple vulnerabilities that could allow root-level command execution and subsequent compromise of customer routers.

Physical access to splitters located in public spaces was also noted as a realistic attack vector that would enable bidirectional traffic interception. Recommended mitigations include mandatory provider-side encryption and consistent use of VPNs by subscribers.

Additional items covered in the same report include the Head Mare group's compromise of TrueConf conferencing servers, the EvilFontTool font-based evasion technique, an OpenAI disclosure regarding an accidental AI-driven attack on Hugging Face, a new Spectre-v2 bypass affecting Intel and AMD processors, and the 18-year-old SCTPhantom (CVE-2026-64564) Linux kernel vulnerability.

Related articles

安全客Vulnerabilities & Exploits

ServiceNow Discloses Three CVSS 10.0 Vulnerabilities Allowing Unauthenticated Remote Code Execution and SQL Injection

ServiceNow has released security updates addressing four vulnerabilities in its AI platform, including three rated CVSS 10.0. The flaws enable unauthenticated attackers to achieve remote code execution, privilege escalation, and arbitrary SQL execution against core ITSM systems used by large enterprises worldwide. Affected components include the GraphQL Composite Data API, system configuration image upload processor, and dynamic schema ORDER BY handling. ServiceNow states it has patched hosted instances and provided hotfixes for self-hosted customers running Xanadu, Yokohama, Zurich, and Australia branches. This follows a July disclosure of a related sandbox escape tracked as CVE-2026-6875 that showed signs of in-the-wild exploitation. No public exploits or confirmed active attacks have been observed for the new issues yet, but the extremely low attack complexity leaves a narrow remediation window for organizations running exposed instances.

HabrVulnerabilities & Exploits

AI Agent Uncovers Unauthenticated Router Config Dump Leading to CVE Filing

An LLM agent tasked only with documenting network topology independently discovered a critical authentication bypass in a home router firmware. The agent performed read-only reconnaissance, extracted the full configuration including base64-encoded admin passwords and WPA2 keys via an unprotected CGI endpoint, and verified the finding by obtaining a valid session cookie. It then produced a complete coordinated disclosure report, classified the issue under CWE-306 with a CVSS 3.1 score of 8.8, and prepared the MITRE CVE submission package. The vulnerability affects LAN-side management interfaces of certain SOHO routers running legacy Boa web servers and remains unpatched due to inaccessible vendor firmware channels. The researcher maintained strict read-only permissions for the agent throughout the process, ensuring no configuration changes occurred. The case demonstrates how autonomous agents can accelerate vulnerability research while staying within defined operational boundaries.

HabrVulnerabilities & Exploits

AutoAddPolicy in Paramiko Disables Host Key Verification and Risks Credential Leakage After IP Reassignment

A developer discovered that fourteen deployment and management scripts all contained hardcoded references to a single VPS IP address. When the provider reassigned the address after migration, the scripts connected to an unrelated server belonging to another customer. The root cause was the line ssh.set_missing_host_key_policy(paramiko.AutoAddPolicy()), which silently accepts any host key instead of raising an exception. The connection succeeded, the root password stored in VPS_PASS was transmitted, and the operation appeared successful in logs. The author replaced AutoAddPolicy with RejectPolicy, centralized the address in a single vps.py module, and switched to key-based authentication with a password fallback. The same class of issue appears in web tools that fetch arbitrary URLs, requiring strict scheme, IP-range, and redirect checks to block SSRF vectors such as 127.0.0.1 and 169.254.169.254. The case demonstrates that host-key verification protects against routine cloud IP reuse rather than only theoretical man-in-the-middle attacks.

HabrVulnerabilities & Exploits

Developer Exposes 12 Vulnerabilities in FastAPI Todo App After 176 Bots Bypass Protections

A developer building a student-focused todo planner on FastAPI discovered that 176 of 238 new accounts were bots that bypassed three layers of protection including rate limiting and email verification. The issues stemmed from in-memory counters reset on every deployment, uvicorn trusting any X-Forwarded-For header, and email verification never being enforced in code. A full audit revealed additional flaws such as stored XSS via JSON-LD on public Q&A pages and an IDOR allowing any authenticated user to read all tasks in a project by supplying its ID. Fixes included moving rate limits to the database, properly extracting the client IP from the rightmost X-Forwarded-For entry, adding signed form timestamps, and escaping JSON for script contexts. The case highlights common pitfalls when deploying Python web services behind nginx without strict trust boundaries.