VYPR
Unrated severityNVD Advisory· Published Feb 10, 2021· Updated Aug 3, 2024

CVE-2021-27170

CVE-2021-27170

Description

An issue was discovered on FiberHome HG6245D devices through RP2613. By default, there are no firewall rules for IPv6 connectivity, exposing the internal management interfaces to the Internet.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

FiberHome HG6245D devices lack IPv6 firewall rules by default, exposing internal management interfaces to the Internet.

Vulnerability

By default, FiberHome HG6245D routers (through firmware RP2613) have no firewall rules for IPv6 connectivity, leaving internal management interfaces accessible over IPv6 from the Internet. This affects all tested firmware versions including RP2602 and the latest RP2613 [1].

Exploitation

An attacker on the WAN can reach internal services (e.g., the web interface) over IPv6 without authentication. The device's default configuration exposes HTTP/HTTPS on the LAN, but due to the missing IPv6 firewall, these services are also reachable from the WAN over IPv6. The attacker can then leverage backdoor credentials or other vulnerabilities to gain further access [1].

Impact

Successful exploitation allows an unauthenticated remote attacker to access internal management interfaces over IPv6, potentially leading to full device compromise including pre-auth RCE as root. All internal services become exposed to the Internet via IPv6 [1].

Mitigation

As of the publication date, no official fix or firmware update has been released to address this issue. Users may consider disabling IPv6 on the WAN interface or implementing external firewall rules to block IPv6 traffic to the device. The latest firmware (RP2613) is still vulnerable [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.