TelcoSec PSTN/ADSL Cyber Range - GenieACS TR-069/CWMP Auto Configuration Server.
445
A GenieACS-based TR-069/CWMP server that remotely provisions every simulated CPE in the lab — pushing SIP and Wi-Fi credentials automatically, exactly like a real ISP's provisioning backend.
Attack surface: unauthenticated MongoDB device database dump on the management network, unencrypted HTTP "Inform" traffic vulnerable to ARP-spoof hijacking, Northbound API (NBI) queries that leak provisioned credentials.
Part of the TelcoSec PSTN/ADSL Cyber Range — a 16-container, 100% software-based telecom security lab modeling a realistic wholesale ISP (copper-line impairments, PPPoE, RADIUS/AAA, L2TP wholesale roaming, TR-069/CWMP). Built for the TelcoSec Telecom Security Academy.
⚠️ Intentionally vulnerable. Ships plaintext PAP/crackable MS-CHAPv2, an unauthenticated MongoDB backend, and unencrypted TR-069 by design, for red-team training. Do not deploy outside an isolated lab network.
Full lab source, architecture diagram, and attack scenarios: https://github.com/TelcoSec-Labs/TelcoSec_PSTN_ADSL_LABs
Content type
Image
Digest
sha256:835d4dcab…
Size
67.4 MB
Last updated
8 days ago
docker pull telecomsecurity/pstn-adsl-acs:main-58948bc