Huawei HG8245 backdoor and remote access
The Huawei HG8245 ONT, firmware version V1R006C00S100 which provides cellular services, contains 3 severe vulnerabilities: two administrator accounts enabled by default and a public administration interface exposed to the Internet.
CVSS Score
Severity
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Advisory
| Device | Huawei HG8245 |
| Hardware | 130C4600 |
| Software | V1R006C00S100 |
| Impact | Default backdoor accounts on web and Telnet with non-changeable passwords |
Description
The Huawei HG8245 ONT ships with two administrative backdoor accounts enabled by default. The passwords cannot be changed from any documented interface.
Backdoor Credentials
Web management interface:
admin:*6P0N4dm1nP4SS*Telnet service:
root:adminBecause these accounts exist even on devices where the operator has changed the primary admin password, anyone with network reachability to the device can fully compromise it.
Remediation
Disable WAN-side HTTP and Telnet access. No vendor-supplied way to change the default backdoor password.