vendor:
EchoLife HG520
by:
hkm
7,5
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: EchoLife HG520
Affected Version From: 3.10.18.7-1.0.7.0
Affected Version To: 3.10.18.4
Patch Exists: YES
Related CWE: N/A
CPE: h:huawei:echolife_hg520
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Python, Scapy and Tcpdump
2010
Huawei EchoLife HG520 Remote Information Disclosure
By sending a specially crafted UDP packet, an attacker can remotely obtain the following information: software and firmware versions, MAC, local and remote IP, model and PPPoE credentials in clear text.
Mitigation:
Ensure that all software and firmware versions are up to date and that all UDP packets are properly filtered.