EIP-2026-101306

PRE-CVE

Huawei EchoLife HG520 - Remote Information Disclosure

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101306. PoCs published by hkm.

AI-analyzed exploit summary This exploit demonstrates a remote information disclosure vulnerability in Huawei EchoLife HG520 routers by sending a crafted UDP packet to extract sensitive data such as firmware versions, MAC addresses, and PPPoE credentials. The PoC requires Python and Scapy to construct and send the malicious packet.

Description

Huawei EchoLife HG520 - Remote Information Disclosure

Exploits (1)

exploitdb WORKING POC
by hkm · textremotehardware
https://www.exploit-db.com/exploits/12298

This exploit demonstrates a remote information disclosure vulnerability in Huawei EchoLife HG520 routers by sending a crafted UDP packet to extract sensitive data such as firmware versions, MAC addresses, and PPPoE credentials. The PoC requires Python and Scapy to construct and send the malicious packet.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Huawei EchoLife HG520 (Firmware: 3.10.18.7-1.0.7.0, 3.10.18.5-1.0.7.0, 3.10.18.4; Software: V100R001B120Telmex, V100R001B121Telmex)
No auth needed
Prerequisites: Python · Scapy · Network access to the target device
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026