VYPR
Unrated severityNVD Advisory· Published Feb 10, 2021· Updated Aug 3, 2024

CVE-2021-27174

CVE-2021-27174

Description

An issue was discovered on FiberHome HG6245D devices through RP2613. wifi_custom.cfg has cleartext passwords and 0644 permissions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

FiberHome HG6245D routers store Wi-Fi credentials in cleartext in a world-readable file, leaking the pre-shared key.

Vulnerability

FiberHome HG6245D GPON FTTH routers running firmware versions RP2602 through RP2613 store Wi-Fi configuration in /fhconf/wifi_custom.cfg. This file contains the Wi-Fi pre-shared key (PSK) and other credentials in cleartext and is assigned permissions 0644, making it readable by any local user or process [1]. The vulnerability is present in all tested firmware versions, including the latest RP2613, and is likely shared across other FiberHome device models due to a common codebase [1].

Exploitation

An attacker who gains any level of access to the device's filesystem—for instance via an existing shell, a web application flaw, or by exploiting the lack of IPv6 firewall to reach internal services—can simply read /fhconf/wifi_custom.cfg [1]. No authentication beyond local user access is required to retrieve the file. On the default LAN-only attack surface, the attacker must first obtain local execution capability, but from the WAN side over IPv6 the internal services are reachable, lowering the barrier [1].

Impact

Successful exploitation reveals the Wi-Fi network's pre-shared key in plaintext, allowing the attacker to decrypt wireless traffic, join the private network, and potentially pivot to other devices on the same LAN. This constitutes a confidentiality breach of network credentials and can lead to further compromise of the home or small-office network [1].

Mitigation

As of February 2021 the vendor had not released a patched firmware that encrypts the credentials or restricts file permissions [1]. No workaround is available beyond limiting IPv6 exposure and ensuring the device's web interface is not accessible from untrusted networks. The device is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.