Remote credential and configuration disclosure of Huawei HG5XX devices using Nmap.

Remote credential and configuration disclosure of Huawei HG5XX devices using Nmap.

Posted on June 05, 2012 by Paulino Calderon

I have added a NSE script called "http-huawei-hg5xx-vuln" which exploits a couple of vulnerabilities found in Huawei HG5XX modems.

The first vulnerability which allows an attacker to extract the router's configuration file, was found by Pedro Joaquín of Websec. The second vulnerability lets the attacker extract the PPPoE password and was reported by ADiaz.

The information extracted by "http-huawei-hg5xx-vuln" is:

  • PPPoE credentials
  • Model
  • Firmware version
  • Gateway IP
  • DNS 1 and 2
  • Network segment
  • Active Ethernet and WiFi connections
  • BSSID

To obtain the Huawei HG5XX's PPPoE credentials and configuration file with Nmap we can use the following command:

$nmap -p80 --script http-huawei-hg5xx-vuln <IP>

If the device is vulnerable:

huawei hg5xx nmap

Here you can see a video demonstrating "http-huawei-hg5xx-vuln" in action:

References

 


Latest Blog Entries

Panoptic
An overview of Panoptic, an open source penetration testing tool that automates the process of search and retrieval of common log and config files through LFI vulnerabilities.
Posted in panoptic python tool lfi

Special discount code for "Nmap 6: Network Exploration and Security Auditing Cookbook"
PacktPub created a special discount code for our friends from HackerHalted
Posted in Nmap Hacker Halted nmap cookbook

Mac2WepKey HHG5xx for iPhone
The famous app to obtain the default WiFi passwords for Huawei routers is now available for the iPhone iOS 5.
Posted in HHG5xx iPhone huawei mac2wepkey passwords generator

Latest News

Oct 12, 2012
Websec at Hacker Halted USA 2012
Hacker Halted USA 2012 will reunite information security specialists from around the world to show the latest and most innovating research in the field of information security.

Sep 27, 2012
Nmap 6: Network Exploration and Security Auditing Cookbook is now on pre-sale!
The book "Nmap 6: Network Exploration and Security Auditing Cookbook" by Paulino Calderón is now on pre-sale and will be available soon.