CVE-2020-37220

Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain administrative access by retrieving the device serial number. Attackers can query the /api/system/deviceinfo endpoint without authentication to extract the SerialNumber field, then use the last 8 characters as the default password to log in to the router.
Configurations

No configuration.

History

26 May 2026, 14:16

Type Values Removed Values Added
Summary (en) Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain administrative access by retrieving the device serial number. Attackers can query the /api/system/deviceinfo endpoint without authentication to extract the SerialNumber field, then use the last 8 characters as the default password to login to the router. (en) Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain administrative access by retrieving the device serial number. Attackers can query the /api/system/deviceinfo endpoint without authentication to extract the SerialNumber field, then use the last 8 characters as the default password to log in to the router.

13 May 2026, 17:07

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-13 16:16

Updated : 2026-05-26 14:16


NVD link : CVE-2020-37220

Mitre link : CVE-2020-37220

CVE.ORG link : CVE-2020-37220


JSON object : View

Products Affected

No product.

CWE
CWE-798

Use of Hard-coded Credentials