GhostSec claims to have disconnected 4,097 CANTV modems via TR-069 during the June 28 elections in Venezuela
Coinciding with Election Day on July 28, 2024, in Venezuela, the hacktivist group GhostSec claimed to have exploited misconfigured modems belonging to the state-owned company CANTV, manipulating passwords, network settings, and the TR-069 remote management protocol to prevent CANTV from reconfiguring them remotely. According to the claim reported by the media, 4,097 modems were taken offline, including the Stavix MP-X421R (1,930), Huawei DG8245V-10 (1,654), ZTE F670L (414), and ZTE ZXH108N v2.5 (99) were disconnected. The group stated that its target was the state-owned company and the government, not the general public, since most users still had 4G mobile access. The figures and scope come from the group’s own statement and were not officially confirmed by CANTV.
Impact details
Report of 4,097 CANTV modems being disconnected (Stavix MP-X421R, Huawei DG8245V-10, ZTE F670L, and ZTE ZXH108N v2.5) by manipulating the TR-069 protocol and changing passwords/configurations, preventing CANTV from remotely reconfiguring the devices on election day. The number of affected devices and the scope of the incident have not been officially confirmed by CANTV.
Classification & severity
- Category
- Availability
- Subtype
- Service outage
- Confidence
- Medium
GhostSec’s detailed report and media coverage describe the disruption of modem operations via the TR-069 protocol, but CANTV has not officially confirmed the number of people affected or the scope of the incident.
Severity assessment
Medium- Functional impact
- Degraded (critical)
- Information impact
- None
- Affected scope
- Multiple users
- Critical service
- Degraded
- Public confidence
- Limited
- Recoverability
- Supplemented
A detailed report—albeit from the author himself—of a disruption in modem operations affecting the telecommunications infrastructure; the number and scope of the incidents have not been officially confirmed.
Timeline
On Election Day, July 28, 2024, GhostSec exploited misconfigured CANTV modems using the TR-069 protocol, changing passwords and network settings.
GhostSec claims responsibility for taking 4,097 modems (Stavix, Huawei, ZTE) offline, stating that the target is the state-owned company and the government, not the general public.
Publimetro Mexico publishes details of the claim, including modem models and counts, as well as the TR-069 method.
Subsequent reports (People's Dispatch / Misión Verdad) place the attack within a broader campaign of cyberattacks against Venezuela following July 28.