VYPR
Unrated severityNVD Advisory· Published Feb 10, 2021· Updated Aug 3, 2024

CVE-2021-27172

CVE-2021-27172

Description

An issue was discovered on FiberHome HG6245D devices through RP2613. A hardcoded GEPON password for root is defined inside /etc/init.d/system-config.sh.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

FiberHome HG6245D devices contain a hardcoded root password for GEPON, allowing attackers to gain root access via telnet.

Vulnerability

An issue was discovered on FiberHome HG6245D devices through firmware version RP2613. A hardcoded GEPON password for the root user is defined inside /etc/init.d/system-config.sh. This static credential is present in all tested firmware versions, including the latest RP2613 [1].

Exploitation

An attacker with network access to the device can exploit this vulnerability. The device exposes HTTP/HTTPS services on the LAN by default, and IPv6 services are reachable from the WAN due to the lack of a firewall [1]. The attacker can use the hardcoded credentials to enable the proprietary CLI telnetd via the web interface, then log in as root using the same credentials. Alternatively, the attacker can directly access the Linux telnetd if it is enabled [1].

Impact

Successful exploitation grants the attacker a root shell on the device, leading to full compromise. This includes the ability to read and modify all device configurations, intercept network traffic, and use the device as a pivot point for further attacks on the internal network [1].

Mitigation

As of the publication date (February 2021), no firmware fix has been released by FiberHome. The latest version RP2613 remains vulnerable. Users should restrict network access to the device, disable IPv6 if not required, and monitor for future firmware updates. No workaround is available [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.