CVE-2021-27151
Description
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded rootmet / m3tr0r00t credentials for an ISP.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
FiberHome HG6245D routers contain hardcoded ISP credentials (rootmet/m3tr0r00t) in the web daemon, allowing remote attackers to gain root access.
Vulnerability
The web daemon on FiberHome HG6245D devices (firmware versions through RP2613) contains hardcoded credentials rootmet / m3tr0r00t intended for an ISP account. This backdoor is present in the HTTP server and allows authentication without any prior access. The vulnerability was confirmed on firmware RP2602 and RP2613, and likely affects other FiberHome models such as AN5506-04-FA [1].
Exploitation
An attacker with network access to the device (LAN via IPv4, or WAN via IPv6 due to lack of IPv6 firewall) can exploit the hardcoded credentials by sending HTTP requests to the web interface. The attacker authenticates using the backdoor credentials, then can enable a proprietary CLI telnetd or directly obtain a root shell via the Linux telnetd. No user interaction is required [1].
Impact
Successful exploitation grants the attacker root-level access to the device, allowing full control over the router. This includes the ability to read and modify configuration, intercept network traffic, launch further attacks on the internal network, and persist access. The compromise is complete and remote [1].
Mitigation
As of the publication date (February 2021), no official firmware patch has been released to remove the hardcoded credentials. Users should restrict network access to the device by disabling remote management, applying strict firewall rules, and isolating the router on a separate VLAN. If possible, replace the device with a patched or alternative model [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- FiberHome/HG6245Ddescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.