VYPR
Unrated severityNVD Advisory· Published Feb 10, 2021· Updated Aug 3, 2024

CVE-2021-27157

CVE-2021-27157

Description

An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 888888 credentials for an ISP.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

FiberHome HG6245D routers contain hardcoded ISP credentials (admin/888888) in the web daemon, allowing attackers to gain administrative access and potentially achieve remote code execution.

Vulnerability

The FiberHome HG6245D router's web daemon contains hardcoded credentials (admin / 888888) intended for ISP use. This issue affects all firmware versions through RP2613 [1]. The credentials are embedded in the HTTP server and can be used to authenticate to the web interface without any prior access.

Exploitation

An attacker with network connectivity to the device's web interface (HTTP/HTTPS on port 80/443) can simply log in using the hardcoded admin and 888888 credentials. The web interface is reachable from the LAN by default, and due to lack of IPv6 firewall, it may also be accessible from the WAN over IPv6 [1]. Once authenticated, the attacker can enable a proprietary CLI telnet daemon and subsequently use additional backdoor credentials to obtain a root shell on the Linux telnet service [1].

Impact

Successful exploitation grants the attacker full administrative control over the router. This includes the ability to read and modify device configuration, intercept or redirect network traffic, and execute arbitrary commands as root, leading to complete compromise of the device and potentially the connected network [1].

Mitigation

As of the publication date (February 2021), no firmware update has been released to address this vulnerability; the latest version RP2613 remains affected [1]. Users should restrict network access to the web interface by disabling remote management and using firewall rules to limit access to trusted IPs. Monitor vendor channels for a future patch. No official workaround is available [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.