VYPR
Unrated severityNVD Advisory· Published Feb 10, 2021· Updated Aug 3, 2024

CVE-2021-27148

CVE-2021-27148

Description

An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded telecomadmin / nE7jA%5m credentials for an ISP.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

FiberHome HG6245D routers contain hardcoded ISP credentials (telecomadmin/nE7jA%5m) in the web daemon, allowing unauthorized access.

Vulnerability

The web daemon on FiberHome HG6245D devices (firmware versions RP2602 through RP2613) contains hardcoded credentials telecomadmin / nE7jA%5m intended for ISP use [1]. These credentials are embedded in the HTTP server and can be used to authenticate to the web interface without any prior access.

Exploitation

An attacker with network access to the device's web interface (typically on LAN, but also reachable over IPv6 from WAN due to lack of firewall) can simply use the hardcoded username and password to log in [1]. No authentication bypass or additional steps are required; the credentials are valid for the web daemon.

Impact

Successful authentication grants the attacker administrative access to the web interface, which can be used to enable telnet services and ultimately obtain a root shell on the device [1]. This leads to full compromise of the router, including the ability to modify configuration, intercept traffic, and pivot into the internal network.

Mitigation

FiberHome has not released a patch for this issue as of the publication date (February 2021) [1]. The latest firmware version RP2613 at the time was also vulnerable. Users should restrict network access to the web interface, disable remote management, and monitor for firmware updates from the vendor. If possible, replace the device with a more secure alternative.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.