TelcoSec PSTN/ADSL Cyber Range - simulated TR-069 CPE/broadband router (PPPoE + genieacs-sim).
141
Simulated home/business broadband router. Each cpe container negotiates a
PPPoE session over a simulated copper link (with realistic packet loss/jitter
via tc/netem) and runs genieacs-sim to register as a real TR-069 device
against the lab's ACS — exposing SIP/Wi-Fi credentials pushed by the ACS and a
full CWMP Data Model surface for exploitation.
Attack surface: plaintext PPPoE PAP / crackable MS-CHAPv2 authentication, unencrypted TR-069 "Inform" messages (ARP-spoofable), auto-provisioned SIP and Wi-Fi credentials pulled from the ACS.
Part of the TelcoSec PSTN/ADSL Cyber Range — a 16-container, 100% software-based telecom security lab modeling a realistic wholesale ISP (copper-line impairments, PPPoE, RADIUS/AAA, L2TP wholesale roaming, TR-069/CWMP). Built for the TelcoSec Telecom Security Academy.
⚠️ Intentionally vulnerable. Ships plaintext PAP/crackable MS-CHAPv2, an unauthenticated MongoDB backend, and unencrypted TR-069 by design, for red-team training. Do not deploy outside an isolated lab network.
Full lab source, architecture diagram, and attack scenarios: https://github.com/TelcoSec-Labs/TelcoSec_PSTN_ADSL_LABs
Content type
Image
Digest
sha256:95c0f5e79…
Size
128.6 MB
Last updated
23 days ago
docker pull telecomsecurity/pstn-adsl-cpe:main-004c145