VYPR
Unrated severityNVD Advisory· Published Feb 10, 2021· Updated Aug 3, 2024

CVE-2021-27166

CVE-2021-27166

Description

An issue was discovered on FiberHome HG6245D devices through RP2613. The password for the enable command is gpon.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

FiberHome HG6245D devices have a hardcoded enable password 'gpon' allowing unauthorized privileged configuration access.

Vulnerability

The FiberHome HG6245D GPON FTTH router, including firmware versions up to RP2613, contains a hardcoded password for the device's enable command in the proprietary CLI. The password is 'gpon' [1]. This vulnerability is present in the CLI accessible via telnet (which can be enabled) and potentially via the web interface. The default configuration does not expose telnet externally, but it can be enabled through hardcoded web credentials or other backdoor mechanisms [1].

Exploitation

An attacker who can reach the device's telnet service (either on the LAN, or over IPv6 from the WAN due to lack of IPv6 firewall, or by first enabling telnet via the web interface using other backdoor credentials) can enter the enable command and provide the hardcoded password 'gpon' [1]. This does not require authentication beforehand if the telnet session is already established with default or backdoor credentials. The steps are: (1) establish a telnet session to the device, (2) type enable, (3) enter the password gpon [1].

Impact

Successful exploitation grants the attacker privileged access to the device's configuration mode (enable-level access) [1]. From there, the attacker can view or modify the device's configuration, potentially gaining full control. This can lead to further compromise, such as enabling additional services, altering network settings, or achieving remote code execution with root privileges, as the device has other vulnerabilities that chain with this one [1].

Mitigation

As of the publication date (2021-02-10), no firmware patch was available; the latest firmware RP2613 is still vulnerable [1]. Users are advised to limit telnet and web access to trusted networks only, disable IPv6 if not required, and monitor for vendor updates. The device has not been listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of this writing.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.