CVE-2021-27148
Description
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded telecomadmin / nE7jA%5m credentials for an ISP.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
FiberHome HG6245D routers contain hardcoded ISP credentials (telecomadmin/nE7jA%5m) in the web daemon, allowing unauthorized access.
Vulnerability
The web daemon on FiberHome HG6245D devices (firmware versions RP2602 through RP2613) contains hardcoded credentials telecomadmin / nE7jA%5m intended for ISP use [1]. These credentials are embedded in the HTTP server and can be used to authenticate to the web interface without any prior access.
Exploitation
An attacker with network access to the device's web interface (typically on LAN, but also reachable over IPv6 from WAN due to lack of firewall) can simply use the hardcoded username and password to log in [1]. No authentication bypass or additional steps are required; the credentials are valid for the web daemon.
Impact
Successful authentication grants the attacker administrative access to the web interface, which can be used to enable telnet services and ultimately obtain a root shell on the device [1]. This leads to full compromise of the router, including the ability to modify configuration, intercept traffic, and pivot into the internal network.
Mitigation
FiberHome has not released a patch for this issue as of the publication date (February 2021) [1]. The latest firmware version RP2613 at the time was also vulnerable. Users should restrict network access to the web interface, disable remote management, and monitor for firmware updates from the vendor. If possible, replace the device with a more secure alternative.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- FiberHome/HG6245Ddescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.