VYPR
Unrated severityNVD Advisory· Published Nov 17, 2023· Updated Sep 4, 2024

CVE-2020-11447

CVE-2020-11447

Description

An issue was discovered on Bell HomeHub 3000 SG48222070 devices. Remote authenticated users can retrieve the serial number via cgi/json-req - this is an information leak because the serial number is intended to prove an actor's physical access to the device.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated remote users can leak the serial number of Bell HomeHub 3000 devices via cgi/json-req, defeating physical-access proof.

Vulnerability

An information disclosure vulnerability exists in the Bell HomeHub 3000 (model SG48222070) firmware. The /cgi/json-req endpoint returns the device's serial number to any remote authenticated user, without requiring proof of physical access. The serial number is intended to verify that an actor is physically near the device, but the API does not enforce any such constraint. The issue affects the Bell HomeHub 3000; the same code path may exist in Home Hub 2000 and above models [1] but the CVE scope is limited to the 3000.

Exploitation

An attacker must have valid credentials (username/password) to the Home Hub's web interface. With those, they can send a crafted HTTP request to /cgi/json-req and retrieve the serial number in the response. No special network position is required beyond being able to reach the device over the LAN or WAN if remote management is enabled.

Impact

Successful exploitation leaks the device's serial number, which is a unique hardware identifier. The serial number is intended to prove that a support or management action is being performed by someone with physical access. Leaking it may allow an attacker to impersonate the device owner in support interactions or use the serial number in further attacks that rely on knowledge of that identifier. No other data (passwords, configuration) is disclosed via this particular endpoint.

Mitigation

As of the publication date (2023-11-17), no firmware patch or official mitigation has been announced by Bell for the HomeHub 3000. Users can reduce exposure by avoiding remote administration, using strong passwords, and restricting network access to the management interface. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.