CVE-2021-27162
Description
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / tattoo@home credentials for an ISP.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
FiberHome HG6245D devices contain hardcoded ISP credentials tattoo@home in the web daemon, allowing LAN attackers to enable telnet and gain root access.
Vulnerability
The FiberHome HG6245D GPON FTTH router, through firmware version RP2613, contains hardcoded credentials (user / tattoo@home) for an ISP account in its HTTP/HTTPS web daemon. This vulnerability is documented by researchers and confirmed on hardware version WKE2.094.277A01 running software versions RP2602 and RP2613. The hardcoded credentials are accessible to any user who can reach the web interface on the LAN (default). [1]
Exploitation
An attacker with LAN access can use the hardcoded credentials to authenticate to the web interface at https://target/fh. Once authenticated, the attacker can enable a proprietary CLI telnet daemon and subsequently enable the Linux telnet daemon, leading to a root shell. The device also lacks firewall rules for IPv6, making internal services reachable from the WAN over IPv6, which broadens the attack surface. [1]
Impact
Successful exploitation allows an unauthenticated attacker (with LAN or, via IPv6, WAN access) to gain a root shell on the device. This results in full compromise of the router, enabling information disclosure, configuration modification, and potential use as a pivot point in the network. [1]
Mitigation
As of the publication date (2021-02-10), no fix or patch has been released by FiberHome for the HG6245D. Users should restrict LAN access to the web interface, disable IPv6 if not needed, and monitor for firmware updates. The device is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog. [1]
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- FiberHome/HG6245Ddescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.