aczire/huawei-csrf-info_disclosure

aczire/huawei-csrf-info_disclosure

Releases0
Stars2
Exploits un-authenticated information disclosure vulnerability in Huawei SOHO routers.

CVE History

CVEPublishedCVSS v3CVSS v2
4.3 MEDIUM

The Huawei E355 adapter with firmware 21.157.37.01.910 does not require authentication for API pages, which allows remote attackers to change passwords and settings, or obtain sensitive information, via a direct request to (1) api/wlan/security-settings, (2) api/device/information, (3) api/wlan/basic-settings, (4) api/wlan/mac-filter, (5) api/monitoring/status, or (6) api/dhcp/settings.