Skip to main content
Blog

Remote credential and configuration disclosure of Huawei HG5XX devices using Nmap.

A new NSE script called "http-huawei-hg5xx-vuln" has been added to Nmap which exploits a couple of vulnerabilities found in Huawei HG5XX modems.

Share this article:
Remote credential and configuration disclosure of Huawei HG5XX devices using Nmap.

I have added a NSE script called "http-huawei-hg5xx-vuln" which exploits a couple of vulnerabilities found in Huawei HG5XX modems.

The first vulnerability which allows an attacker to extract the router's configuration file, was found by Pedro Joaquín of Websec. The second vulnerability lets the attacker extract the PPPoE password and was reported by ADiaz.

The information extracted by "http-huawei-hg5xx-vuln" is:

  • PPPoE credentials
  • Model
  • Firmware version
  • Gateway IP
  • DNS 1 and 2
  • Network segment
  • Active Ethernet and WiFi connections
  • BSSID

To obtain the Huawei HG5XX's PPPoE credentials and configuration file with Nmap we can use the following command:

$nmap -p80 --script http-huawei-hg5xx-vuln <IP>

If the device is vulnerable:

huawei hg5xx nmap

Here you can see a video demonstrating "http-huawei-hg5xx-vuln" in action:

References

Follow our research

Get new articles and security advisories as soon as they are published.

Related Articles

Discover more cybersecurity insights and solutions to help strengthen your organization's security posture

A Comparison Between the Real User ID and the Effective User ID is not Enough to Prevent Privilege Escalation
Blog

A Comparison Between the Real User ID and the Effective User ID is not Enough to Prevent Privilege Escalation

In Unix-like systems, processes have a real and effective user ID determining their access permissions. While usually identical, they can differ in situations like when the setuid bit is activated in executables.

Websec DevSecOps Webinar
Blog

Websec DevSecOps Webinar

Roberto Salgado and Kobalt.io's Miki Fukushima are hosting a free webinar on September 20, 2022 covering why application security matters, the shift to developer-first security, and a practical roadmap for embedding security into DevSecOps.

CVE-2022-21404: Another story of developers fixing vulnerabilities unknowingly because of CodeQL
Blog

CVE-2022-21404: Another story of developers fixing vulnerabilities unknowingly because of CodeQL

How CodeQL may help reduce false negatives within Open-Source projects. Taking a look into a deserialization vulnerability within Oracle Helidon (CVE-2022-21404).