CVE-2020-37220

HIGH

Huawei HG630 V2 Router Authentication Bypass via Serial Number

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-37220. PoCs published by Eslam Medhat.

AI-analyzed exploit summary The exploit demonstrates an authentication bypass in Huawei HG630 V2 routers by leaking the device's serial number via an unauthenticated API endpoint, which is then used to derive the default password.

Description

Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain administrative access by retrieving the device serial number. Attackers can query the /api/system/deviceinfo endpoint without authentication to extract the SerialNumber field, then use the last 8 characters as the default password to log in to the router.

Exploits (1)

exploitdb WORKING POC
by Eslam Medhat · textwebappshardware
https://www.exploit-db.com/exploits/48310

The exploit demonstrates an authentication bypass in Huawei HG630 V2 routers by leaking the device's serial number via an unauthenticated API endpoint, which is then used to derive the default password.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Huawei HG630 V2 (HardwareVersion: VER.B)
No auth needed
Prerequisites: Network access to the router's web interface
devstral-2 · analyzed May 13, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-48310
https://www.exploit-db.com/exploits/48310
Third Party Advisory third-party-advisory
Reference
https://www.youtube.com/watch?v=vOrIL7L_cVc
Third Party Advisory third-party-advisory
VulnCheck Advisory: Huawei HG630 V2 Router Authentication Bypass via Serial Number
https://www.vulncheck.com/advisories/huawei-hg630-v2-router-authentication-bypass-via-serial-number

Scores

CVSS v3 7.5
EPSS 0.0036
EPSS Percentile 27.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-798
Status published
Products (2)
www.huawei.com/HG630 V2 Router
www.huawei.com/Huawei HG630 Router HG630 V2
Published May 13, 2026
Tracked Since May 13, 2026