VYPR
Unrated severityNVD Advisory· Published Feb 10, 2021· Updated Aug 3, 2024

CVE-2021-27158

CVE-2021-27158

Description

An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded L1vt1m4eng / 888888 credentials for an ISP.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

FiberHome HG6245D routers contain hardcoded ISP credentials (L1vt1m4eng/888888) in the web daemon, allowing remote attackers to gain root access.

Vulnerability

The web daemon on FiberHome HG6245D devices (through firmware RP2613) contains hardcoded credentials L1vt1m4eng / 888888 intended for an ISP. These credentials are present in the HTTP server and can be used to authenticate to the web interface. The vulnerability affects all firmware versions up to and including RP2613 [1].

Exploitation

An attacker with network access to the device's web interface (typically LAN, but also reachable over IPv6 from WAN due to lack of firewall) can use the hardcoded credentials to log in. Once authenticated, the attacker can enable a proprietary CLI telnetd and subsequently enable the Linux telnetd, ultimately gaining a root shell on the device [1].

Impact

Successful exploitation allows an attacker to gain full root access to the device. This leads to complete compromise of confidentiality, integrity, and availability, including the ability to modify device configuration, intercept traffic, and launch further attacks from the compromised device [1].

Mitigation

As of the publication date (February 10, 2021), no official patch has been released. The latest firmware version RP2613 is also vulnerable. Users should restrict network access to the device's management interface, disable remote management if possible, and monitor for firmware updates from FiberHome. The device may be at end-of-life; no fix is confirmed [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.