Huawei EchoLife HG520c Information Disclosure
Huawei EchoLife HG520 modems are vulnerable to an information disclosure vulnerability. Sensitive modem information can be accessed using a public URL in modems with the web interface activated.
CVSS Score
Severity
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Advisory
| Device | Huawei EchoLife HG520c |
| Firmware | 3.10.18.7-1.0.7.0, 3.10.18.5-1.0.7.0 |
| Software | V100R001B021Telmex, V100R001B020Telmex |
| Location | Web administration interface (LAN/WAN) |
| Websec Advisory | WS10-11 |
Description
The page /Listadeparametros.html reveals software version, internal IP, SSID, and other sensitive modem information. No authentication is required to access it.
Exploit / Proof of Concept
From the LAN (or client-side with the WAN interface disabled):
http://192.168.1.254/Listadeparametros.htmlIf the remote admin interface is enabled on the WAN:
https://<router-wan-ip>/Listadeparametros.htmlRemediation
Disable remote web administration; apply vendor firmware update if available.