# Is the GenieACS provisioning script example flawed?

**URL:** <https://forum.genieacs.com/t/is-the-genieacs-provisioning-script-example-flawed/764>\
**Category:** Uncategorized\
**Created:** [May 7, 2020, 6:41pm UTC](https://forum.genieacs.com/t/is-the-genieacs-provisioning-script-example-flawed/764 "2020-05-07T18:41:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![LuKePicci](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.genieacs.com/lukepicci/32/171_2.png) [@LuKePicci](https://forum.genieacs.com/u/LuKePicci)\
**Post date:** [May 7, 2020, 6:41pm UTC](https://forum.genieacs.com/t/is-the-genieacs-provisioning-script-example-flawed/764/1 "2020-05-07T18:41:06Z")

</div>

I think the provided provisioning flow example is probably flawed. It looks like some info (PPPoE creds in that case) are being selected depending on DeviceId.SerialNumber but its value is not being verified for previous successful authentication. This means Alice, with valid TLS certs (or HTTP credentials) for subject (or username) “001122-CPE001-EXAMPLE” would easily get Bob’s CPE002 PPPoE configurations by sending “CPE002” as DeviceId.SerialNumber value. Am I wrong? Is GenieACS always trusting unauthenticated DeviceId.\* values in general?

```
let model = declare("InternetGatewayDevice.DeviceInfo.ModelName", {value: 1}).value[0];
let serialNumber = declare("DeviceID.SerialNumber", {value: 1}).value[0];
let productClass = declare("DeviceID.ProductClass", {value: 1}).value[0];
let oui = declare("DeviceID.OUI", {value: 1}).value[0];
let args = {serial: serialNumber, productClass: productClass, oui: oui};

//Get the PPPoE creds
let config = ext('cpe-config', 'resetPppoe', JSON.stringify(args));
…

```

From [https://github.com/genieacs/genieacs/wiki/Example-of-a-Provisioning-Flow/1dd24dd6f9920ed3ec3b3affd0d0dc8d757f51af](https://github.com/genieacs/genieacs/wiki/Example-of-a-Provisioning-Flow/1dd24dd6f9920ed3ec3b3affd0d0dc8d757f51af)

---

<div class="post-metadata">

**Author:** ![akcoder](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.genieacs.com/akcoder/32/11_2.png) [@akcoder](https://forum.genieacs.com/u/akcoder)\
**Post date:** [May 7, 2020, 8:26pm UTC](https://forum.genieacs.com/t/is-the-genieacs-provisioning-script-example-flawed/764/2 "2020-05-07T20:26:34Z")

</div>

Yes if you spoof the a CWMP client and spoof the serial number, product class and oui based on this provision script (which I wrote) you would get the credentials for the spoofed device. Do you know of a way around this? Because I sure as heck don’t. I mean you can implement device to CWMP authentication, and that would help, but ultimately if an attacker can get those, all bets are off.

Here is what I can tell you from experience. This script has been in production for 3-4 yrs with no issues.

---

<div class="post-metadata">

**Author:** ![LuKePicci](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.genieacs.com/lukepicci/32/171_2.png) [@LuKePicci](https://forum.genieacs.com/u/LuKePicci)\
**Post date:** [May 7, 2020, 9:06pm UTC](https://forum.genieacs.com/t/is-the-genieacs-provisioning-script-example-flawed/764/3 "2020-05-07T21:06:26Z")

</div>

It is fine if all users share the same PPPoE credentials and settings. Otherwise you should check if the serial number in HTTP credentials (different user/pass for each users of course) or subject name in TLS client certificate (again,.different subject and different keys for each user) matches that one in DeviceId elements received from CPE

There is no other option as far as I know.
