CVE-2020-11447
MEDIUMBell HomeHub 3000 SG48222070 - Authenticated Serial Number Exposure via cgi/json-req
Title source: llmDescription
An issue was discovered on Bell HomeHub 3000 SG48222070 devices. Remote authenticated users can retrieve the serial number via cgi/json-req - this is an information leak because the serial number is intended to prove an actor's physical access to the device.
References (2)
Core 2
Core References
Exploit
https://0xem.ma/posts/HH3K-CVE/
Scores
CVSS v3
4.3
EPSS
0.0065
EPSS Percentile
46.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (1)
bell/home_hub_3000_firmware
sg48222070
Published
Nov 17, 2023
Tracked Since
Feb 18, 2026