CVE-2021-27159
Description
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded useradmin / 888888 credentials for an ISP.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
FiberHome HG6245D devices contain hardcoded credentials (useradmin/888888) for the web daemon, allowing ISP-level access.
Vulnerability
The FiberHome HG6245D GPON FTTH router, up to firmware version RP2613, contains hardcoded credentials useradmin / 888888 for the ISP account in the web daemon (httpd). This issue was discovered and publicly disclosed by Pierrick Kim. The vulnerability is present in all tested firmware versions, including RP2602 and RP2613, and likely affects other FiberHome models such as the AN5506-04-FA [1].
Exploitation
An attacker with network access to the device's web interface (typically LAN, but also reachable over IPv6 from the WAN due to lack of IPv6 firewall) can authenticate using the hardcoded credentials useradmin / 888888 [1]. No prior authentication or user interaction is required. The attacker can then enable a telnet service and use additional backdoor credentials to gain a root shell [1].
Impact
Successful exploitation allows an attacker to gain administrative access to the router, enabling full control over the device. This can lead to complete compromise of the device's configuration, interception or modification of traffic, and potential lateral movement within the network. The impact is considered high as it exposes the ISP-level credentials and allows privilege escalation to root [1].
Mitigation
As of the publication date (2021-02-10), no official fix or firmware update has been released by FiberHome. The latest firmware version RP2613 remains vulnerable [1]. Users are advised to restrict network access to the device's management interface, firewall IPv6 traffic, and monitor for any vendor updates. The device is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of this writing.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- FiberHome/HG6245Ddescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.