Authentication Bypass Weakness in Huawei HG630 V2 Router
CVE-2020-37220
Key Information:
- Vendor
Www.huawei.com
- Status
- Vendor
- CVE Published:
- 13 May 2026
Badges
What is CVE-2020-37220?
The Huawei HG630 V2 router is susceptible to an authentication bypass flaw that permits unauthenticated attackers to gain administrative control without proper credentials. This is achieved by accessing the device's /api/system/deviceinfo endpoint, which reveals the device's serial number. Malicious actors can exploit this information by leveraging the last eight digits of the serial number as a default password, thereby compromising the router's security and allowing unauthorized access to manage network settings.
Affected Version(s)
Huawei HG630 Router HG630 V2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
