Skip to main content
Medium

Huawei EchoLife HG520c Information Disclosure

Huawei EchoLife HG520 modems are vulnerable to an information disclosure vulnerability. Sensitive modem information can be accessed using a public URL in modems with the web interface activated.

CVSS Score
5.3 / 10.0
Severity
Medium
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Advisory

DeviceHuawei EchoLife HG520c
Firmware3.10.18.7-1.0.7.0, 3.10.18.5-1.0.7.0
SoftwareV100R001B021Telmex, V100R001B020Telmex
LocationWeb administration interface (LAN/WAN)
Websec AdvisoryWS10-11

Description

The page /Listadeparametros.html reveals software version, internal IP, SSID, and other sensitive modem information. No authentication is required to access it.

Exploit / Proof of Concept

From the LAN (or client-side with the WAN interface disabled):

http://192.168.1.254/Listadeparametros.html

If the remote admin interface is enabled on the WAN:

https://<router-wan-ip>/Listadeparametros.html

Remediation

Disable remote web administration; apply vendor firmware update if available.

Share this advisory:

Related Security Advisories

Stay informed about other recent vulnerabilities and security advisories

Medium

Ladybird JSON Parser UTF-8 Validation Denial of Service

Invalid UTF-8 input could crash Ladybird's JSON parser with SIGILL, causing a denial of service in applications processing untrusted JSON. Discovered by Websec co-founder Paulino Calderon.

Severity:
CVSS: 5.5
View advisory
Critical

Command Execution and Backdoor in Zhone GPON-2520

This post will describe a backdoor account found in the Zhone GPON-2520 and will provide a PoC which can be used to disable the firewall filtration rules in order to allow access to services such as ssh, telnet and ftp.

Severity:
CVSS: 9.8
View advisory
High

Huawei HG8245 / HG8247 WPA Generator

Huawei HG8245 & HG8247 ONT (firmware version V1R006C00S100) rely on a weak algorithm to calculate the WPA keys, keys can be predicted easily using the WiFi's MAC Address (BSSID).

Severity:
CVSS: 7.4
View advisory