Skip to content

Releases: coolrecep/Huawei-HG8245X6-Root

HEKZExploit: Huawei HG8245X6 Automated Root & Decryption Toolkit v1.2.0

Choose a tag to compare

@coolrecep coolrecep released this 04 Oct 23:14
f7624c9

v1.2 — 2026-10-05

  • Added device configuration file (hw_ctree) decryption: Extracts PPPoE username and password, web accounts, and the factory password.
  • Added password verification: sUser/admin passwords are now compared directly against the device's own hash—eliminating the risk of incorrect password attempts and account lockouts.
  • Added login support for devices running 2025 firmware (includes new session routing and cookie compatibility).
  • Automatic username fallback: If the default admin login fails, alternative administrator accounts are automatically attempted.
  • TR-069 disablement fix: Enforces administrator login, navigates to the correct settings page, and verifies changes by reading back from the device.
  • Merged PPPoE and Configuration buttons into a single action (🌐 PPPoE).
  • Configuration file compression fix—ensures full-size uncompressed output.
  • Improved timeout handling and connection resilience.

v1.1

  • Setup wizard and automated Python installation.
  • Single-instance protection and required administrator privilege execution.
  • Integrated requirements checking directly into the START flow.
  • Added anti-reverse engineering protection.

HEKZExploit: Huawei HG8245X6 Automated Root & Decryption Toolkit v1.0

Choose a tag to compare

@coolrecep coolrecep released this 04 Oct 13:41
f7624c9

This release provides a fully automated, one-click Windows GUI tool to achieve root access (srv_ssmp) on ISP-locked Huawei OptiXstar HG8245X6 GPON terminals. It completely eliminates the need for hardware teardowns or offline key generation.

🚀 Key Features

  • Direct Credential Extraction: The offline keygen approach has been completely retired. The tool now directly extracts the original sUser root password, PPPoE (ISP) credentials, and Wi-Fi passwords straight from the router's internal customizepara.txt file.
  • Automated Root Execution: Simply plug a blank NTFS-formatted USB drive into the router, and the tool handles the payload execution in seconds to grant full access.
  • TR-069 (ACS) Killswitch: Automatically disables PeriodicInformEnable and EnableCWMP to permanently sever the ISP's remote management access, preventing them from overriding your custom configurations or pushing firmware updates.

👥 Credits & Acknowledgments

  • Vulnerability Discovery: The foundational vulnerability was discovered by the security researchers at Foulab.
  • Exploit Automation: The exploit was perfected, automated, and wrapped into the final GUI by HEKZ (Emirhan Korkmaz).
  • Testing & Research: Extensive hardware teardowns, reverse engineering, and tool testing conducted by cool_recep.