Repository navigation
Releases: coolrecep/Huawei-HG8245X6-Root
Releases · coolrecep/Huawei-HG8245X6-Root
Release list
HEKZExploit: Huawei HG8245X6 Automated Root & Decryption Toolkit v1.2.0
v1.2 — 2026-10-05
- Added device configuration file (
hw_ctree) decryption: Extracts PPPoE username and password, web accounts, and the factory password. - Added password verification:
sUser/adminpasswords are now compared directly against the device's own hash—eliminating the risk of incorrect password attempts and account lockouts. - Added login support for devices running 2025 firmware (includes new session routing and cookie compatibility).
- Automatic username fallback: If the default
adminlogin fails, alternative administrator accounts are automatically attempted. - TR-069 disablement fix: Enforces administrator login, navigates to the correct settings page, and verifies changes by reading back from the device.
- Merged PPPoE and Configuration buttons into a single action (🌐 PPPoE).
- Configuration file compression fix—ensures full-size uncompressed output.
- Improved timeout handling and connection resilience.
v1.1
- Setup wizard and automated Python installation.
- Single-instance protection and required administrator privilege execution.
- Integrated requirements checking directly into the START flow.
- Added anti-reverse engineering protection.
HEKZExploit: Huawei HG8245X6 Automated Root & Decryption Toolkit v1.0
This release provides a fully automated, one-click Windows GUI tool to achieve root access (srv_ssmp) on ISP-locked Huawei OptiXstar HG8245X6 GPON terminals. It completely eliminates the need for hardware teardowns or offline key generation.
🚀 Key Features
- Direct Credential Extraction: The offline keygen approach has been completely retired. The tool now directly extracts the original
sUserroot password, PPPoE (ISP) credentials, and Wi-Fi passwords straight from the router's internalcustomizepara.txtfile. - Automated Root Execution: Simply plug a blank NTFS-formatted USB drive into the router, and the tool handles the payload execution in seconds to grant full access.
- TR-069 (ACS) Killswitch: Automatically disables
PeriodicInformEnableandEnableCWMPto permanently sever the ISP's remote management access, preventing them from overriding your custom configurations or pushing firmware updates.
👥 Credits & Acknowledgments
- Vulnerability Discovery: The foundational vulnerability was discovered by the security researchers at Foulab.
- Exploit Automation: The exploit was perfected, automated, and wrapped into the final GUI by HEKZ (Emirhan Korkmaz).
- Testing & Research: Extensive hardware teardowns, reverse engineering, and tool testing conducted by cool_recep.