VYPR
Unrated severityNVD Advisory· Published Feb 10, 2021· Updated Aug 3, 2024

CVE-2021-27140

CVE-2021-27140

Description

An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to find passwords and authentication cookies stored in cleartext in the web.log HTTP logs.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cleartext passwords and authentication cookies in FiberHome HG6245D HTTP logs allow local attackers to gain admin access.

Vulnerability

The FiberHome HG6245D router (up to and including firmware RP2613) stores passwords and authentication cookies in cleartext in its web.log HTTP logs [1]. This affects the built-in HTTP/HTTPS server listening on the LAN side by default [1]. The vulnerability is present in firmware versions RP2602 and RP2613, and likely affects other FiberHome models (e.g., AN5506-04-FA) due to a shared codebase [1].

Exploitation

An attacker with local network access (LAN side) can access the log file via the web interface, or if any other attack vector (e.g., IPv6 WAN connectivity) allows reading the logs. The logs contain cleartext credentials and cookies exchanged during web administration sessions [1]. No special privileges are required beyond the ability to reach the device's HTTP service and read the logs.

Impact

Successful exploitation allows an attacker to extract valid administrative login credentials and session cookies from the logs. With these, the attacker can log into the web admin interface and gain full administrative control over the router, including the ability to change configurations, enable a backdoor telnet daemon, or perform further attacks [1].

Mitigation

As of publication (February 2021), FiberHome has not released a fix. The latest firmware version RP2613 is still vulnerable [1]. No workaround is documented. Users are advised to limit access to the management interface to trusted networks only, monitor logs for unauthorized access, and check for firmware updates from the vendor.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.