vendor:
Home Gateway
by:
Fady Mohamed Osman
7.5
CVSS
HIGH
Password Disclosure
200
CWE
Product Name: Home Gateway
Affected Version From: UPnP/1.0 IGD/1.00
Affected Version To: UPnP/1.0 IGD/1.00
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: HG530, HG520b
2015
Huawei Home Gateway password disclosure
This exploit allows an attacker to gain access to the password of a Huawei Home Gateway device. The exploit sends a SOAP request to the device on port 80, and the response contains the password of the device. The exploit was tested on the HG530 and HG520b devices provided by TE-DATA Egypt.
Mitigation:
Ensure that the Huawei Home Gateway device is not exposed to the public internet, and that it is behind a firewall. Additionally, ensure that the device is running the latest version of the firmware.