CVE-2021-27156
CRITICALFiberHome HG6245D Firmware < RP2613 - Use of Hard-coded Credentials
Title source: llmDescription
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains credentials for an ISP that equal the last part of the MAC address of the br0 interface.
References (1)
Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.html#httpd-hardcoded-credentials
Scores
CVSS v3
9.8
EPSS
0.1454
EPSS Percentile
96.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-798
Status
published
Products (1)
fiberhome/hg6245d_firmware
< rp2613
Published
Feb 10, 2021
Tracked Since
Feb 18, 2026