CVE-2021-27143
Description
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / user1234 credentials for an ISP.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
FiberHome HG6245D devices contain hardcoded credentials (user/user1234) in the web daemon, allowing ISP-level access.
Vulnerability
FiberHome HG6245D GPON FTTH routers, including firmware versions up to RP2613, have hardcoded credentials (user / user1234) for an ISP account in the web daemon (HTTP/HTTPS). This issue was discovered by security researcher Pierre Kim and is detailed in advisory [1]. The vulnerable device runs software version RP2602 or RP2613; other FiberHome models may also be affected due to shared codebase [1].
Exploitation
An attacker on the same LAN can reach the web interface (default HTTP/HTTPS) and authenticate using the hardcoded credentials. No additional privileges or user interaction are required. Once logged in, the attacker can enable a telnet daemon (CLI) via the web interface and use the same or similar hardcoded credentials to obtain a root shell [1]. The attack is trivial for LAN-based attackers; over IPv6, internal services may be reachable from the Internet due to lack of firewall rules [1].
Impact
Successful exploitation gives the attacker full control of the device with root privileges, leading to complete compromise of confidentiality, integrity, and availability. The attacker can monitor traffic, modify device settings, or use the router as a pivot point [1].
Mitigation
As of the publication date (2021-02-10), the latest firmware version RP2613 remains vulnerable, and no official patch or workaround has been provided by FiberHome. Users should restrict LAN access to the device, disable remote management, and monitor for future firmware updates. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- FiberHome/HG6245Ddescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.