vendor:
HG630 V2
by:
Eslam Medhat
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: HG630 V2
Affected Version From: HG630 V2
Affected Version To: HG630 V2
Patch Exists: NO
Related CWE: N/A
CPE: h:huawei:hg630_v2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2020
Huawei HG630 2 Router – Authentication Bypass
An attacker can leak the serial number of the router via the web app API and use it to login to the router.
Mitigation:
Change the default password of the router.