CVE-2021-27175
Description
An issue was discovered on FiberHome HG6245D devices through RP2613. wifictl_2g.cfg has cleartext passwords and 0644 permissions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
FiberHome HG6245D stores Wi-Fi credentials in cleartext in wifictl_2g.cfg with world-readable permissions, allowing local attackers to extract them.
Vulnerability
The FiberHome HG6245D device, including firmware versions up to RP2613, stores the wireless configuration file wifictl_2g.cfg in cleartext with 0644 permissions, making the file readable by any user on the system. This file contains Wi-Fi passwords (and potentially other credentials) without encryption or obfuscation [1].
Exploitation
An attacker with local access to the device (e.g., via a shell obtained through another vulnerability, or physical access) can simply read /tmp/wifictl_2g.cfg or its location in the filesystem to retrieve the cleartext passwords. No authentication or special privilege is required beyond the ability to execute a file read command [1].
Impact
Successful exploitation leads to disclosure of Wi-Fi credentials, allowing the attacker to connect to the wireless network and perform further attacks on networked devices. This compromises confidentiality of network access credentials [1].
Mitigation
As of the publication date (2021-02-10), firmware version RP2613 is still vulnerable. No fix has been released by FiberHome. Restrict physical and logical access to the device to trusted users only. Monitor for future firmware updates that may address this issue [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- FiberHome/HG6245Ddescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.