VYPR
Unrated severityNVD Advisory· Published Feb 10, 2021· Updated Aug 3, 2024

CVE-2021-27149

CVE-2021-27149

Description

An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded adminpldt / z6dUABtl270qRxt7a2uGTiw credentials for an ISP.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

FiberHome HG6245D routers contain hardcoded ISP credentials (adminpldt/z6dUABtl270qRxt7a2uGTiw) in the web daemon, allowing root access.

Vulnerability

The FiberHome HG6245D GPON FTTH router, through firmware version RP2613, contains hardcoded credentials adminpldt / z6dUABtl270qRxt7a2uGTiw in the web daemon (HTTP/HTTPS) intended for ISP access [1]. These credentials are present in all tested firmware versions, including RP2602 and RP2613, and likely affect other FiberHome models with similar codebases such as AN5506-04-FA [1].

Exploitation

An attacker with network access to the router's web interface (LAN via IPv4/IPv6, or WAN if IPv6 connectivity is enabled) can authenticate using the hardcoded credentials [1]. Once authenticated, they can enable a proprietary CLI telnetd and subsequently the Linux telnetd, ultimately obtaining a root shell on the device [1]. No user interaction beyond network access is required.

Impact

Successful exploitation allows the attacker to gain full root access to the router, leading to complete compromise of the device [1]. This enables arbitrary command execution, configuration changes, and potential use of the device as a pivot point within the network.

Mitigation

As of the latest firmware version RP2613, the hardcoded credentials remain present and no official fix has been released [1]. Users are advised to restrict network access to the web interface, particularly from untrusted networks such as the Internet, and monitor for any vendor-supplied updates. There is no indication that this CVE has been added to the CISA Known Exploited Vulnerabilities catalog at the time of publication.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.