Junglewise Threat Intelligence

CVE-2020-37220: Huawei HG630 V2 authentication bypass via serial number leak

CVE-2020-37220 · Severity: high · CVSS 7.5 · Published 2026-05-13

Vendors: Huawei.

Executive brief

The Huawei HG630 V2 is a home and small office router used to provide internet connectivity. A security flaw allows unauthorized individuals to remotely access the router's administrative interface by retrieving the device's serial number through a public web link. Once logged in, an attacker can change network settings, monitor internet traffic, or disrupt service for the household or business.

Technical details

An authentication bypass vulnerability exists in the Huawei HG630 V2 router due to improper access control on a system information endpoint. An unauthenticated attacker can send a GET request to the /api/system/deviceinfo endpoint to retrieve a JSON response containing the device's SerialNumber. Because the router's default administrative password is derived from the last 8 characters of this serial number, an attacker can use this information to gain full administrative access to the web management interface. This vulnerability is categorized as a use of hard-coded or predictable credentials (CWE-798). Public exploits have been available since 2020.

Affected products

  • Huawei HG630 V2 HG630 V2 and earlier

Timeline

  • 2020-04-13: disclosed: Initial exploit and proof of concept published on Exploit-DB
  • 2026-05-13: advisory: CVE published/updated in NVD via VulnCheck

References