HG6245D
by Fiberhome
CVEs (41)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-4464 | Cri | 0.61 | — | 0.01 | Nov 12, 2025 | FiberHome AN5506-04-FA firmware versions up to and including RP2631 and HG6245D prior to RP2602 contain a stack-based buffer overflow, as the HTTP service ('webs') fails to enforce maximum lengths for Cookie header values. When a cookie longer than 511 bytes is processed, a… | ||
| CVE-2021-27139 | 0.00 | — | 0.00 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to extract information from the device without authentication by disabling JavaScript and visiting /info.asp. | |||
| CVE-2021-27140 | 0.00 | — | 0.00 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to find passwords and authentication cookies stored in cleartext in the web.log HTTP logs. | |||
| CVE-2021-27141 | 0.00 | — | 0.01 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. Credentials in /fhconf/umconfig.txt are obfuscated via XOR with the hardcoded *j7a(L#yZ98sSd5HfSgGjMj8;Ss;d)(*&^#@$a2s0i3g key. (The webs binary has details on how XOR is used.) | |||
| CVE-2021-27142 | 0.00 | — | 0.00 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web management is done over HTTPS, using a hardcoded private key that has 0777 permissions. | |||
| CVE-2021-27143 | 0.00 | — | 0.01 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / user1234 credentials for an ISP. | |||
| CVE-2021-27144 | 0.00 | — | 0.01 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded f~i!b@e#r$h%o^m*esuperadmin / s(f)u_h+g|u credentials for an ISP. | |||
| CVE-2021-27145 | 0.00 | — | 0.00 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / lnadmin credentials for an ISP. | |||
| CVE-2021-27146 | 0.00 | — | 0.00 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / CUadmin credentials for an ISP. | |||
| CVE-2021-27147 | 0.00 | — | 0.01 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / admin credentials for an ISP. | |||
| CVE-2021-27148 | 0.00 | — | 0.00 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded telecomadmin / nE7jA%5m credentials for an ISP. | |||
| CVE-2021-27149 | 0.00 | — | 0.00 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded adminpldt / z6dUABtl270qRxt7a2uGTiw credentials for an ISP. | |||
| CVE-2021-27150 | 0.00 | — | 0.01 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded gestiontelebucaramanga / t3l3buc4r4m4ng42013 credentials for an ISP. | |||
| CVE-2021-27151 | 0.00 | — | 0.01 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded rootmet / m3tr0r00t credentials for an ISP. | |||
| CVE-2021-27152 | 0.00 | — | 0.01 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded awnfibre / fibre@dm!n credentials for an ISP. | |||
| CVE-2021-27153 | 0.00 | — | 0.00 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded trueadmin / admintrue credentials for an ISP. | |||
| CVE-2021-27154 | 0.00 | — | 0.00 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / G0R2U1P2ag credentials for an ISP. | |||
| CVE-2021-27155 | 0.00 | — | 0.00 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 3UJUh2VemEfUtesEchEC2d2e credentials for an ISP. | |||
| CVE-2021-27156 | 0.00 | — | 0.01 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains credentials for an ISP that equal the last part of the MAC address of the br0 interface. | |||
| CVE-2021-27157 | 0.00 | — | 0.01 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 888888 credentials for an ISP. |
- risk 0.61cvss —epss 0.01
FiberHome AN5506-04-FA firmware versions up to and including RP2631 and HG6245D prior to RP2602 contain a stack-based buffer overflow, as the HTTP service ('webs') fails to enforce maximum lengths for Cookie header values. When a cookie longer than 511 bytes is processed, a…
- CVE-2021-27139Feb 10, 2021risk 0.00cvss —epss 0.00
An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to extract information from the device without authentication by disabling JavaScript and visiting /info.asp.
- CVE-2021-27140Feb 10, 2021risk 0.00cvss —epss 0.00
An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to find passwords and authentication cookies stored in cleartext in the web.log HTTP logs.
- CVE-2021-27141Feb 10, 2021risk 0.00cvss —epss 0.01
An issue was discovered on FiberHome HG6245D devices through RP2613. Credentials in /fhconf/umconfig.txt are obfuscated via XOR with the hardcoded *j7a(L#yZ98sSd5HfSgGjMj8;Ss;d)(*&^#@$a2s0i3g key. (The webs binary has details on how XOR is used.)
- CVE-2021-27142Feb 10, 2021risk 0.00cvss —epss 0.00
An issue was discovered on FiberHome HG6245D devices through RP2613. The web management is done over HTTPS, using a hardcoded private key that has 0777 permissions.
- CVE-2021-27143Feb 10, 2021risk 0.00cvss —epss 0.01
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / user1234 credentials for an ISP.
- CVE-2021-27144Feb 10, 2021risk 0.00cvss —epss 0.01
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded f~i!b@e#r$h%o^m*esuperadmin / s(f)u_h+g|u credentials for an ISP.
- CVE-2021-27145Feb 10, 2021risk 0.00cvss —epss 0.00
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / lnadmin credentials for an ISP.
- CVE-2021-27146Feb 10, 2021risk 0.00cvss —epss 0.00
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / CUadmin credentials for an ISP.
- CVE-2021-27147Feb 10, 2021risk 0.00cvss —epss 0.01
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / admin credentials for an ISP.
- CVE-2021-27148Feb 10, 2021risk 0.00cvss —epss 0.00
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded telecomadmin / nE7jA%5m credentials for an ISP.
- CVE-2021-27149Feb 10, 2021risk 0.00cvss —epss 0.00
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded adminpldt / z6dUABtl270qRxt7a2uGTiw credentials for an ISP.
- CVE-2021-27150Feb 10, 2021risk 0.00cvss —epss 0.01
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded gestiontelebucaramanga / t3l3buc4r4m4ng42013 credentials for an ISP.
- CVE-2021-27151Feb 10, 2021risk 0.00cvss —epss 0.01
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded rootmet / m3tr0r00t credentials for an ISP.
- CVE-2021-27152Feb 10, 2021risk 0.00cvss —epss 0.01
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded awnfibre / fibre@dm!n credentials for an ISP.
- CVE-2021-27153Feb 10, 2021risk 0.00cvss —epss 0.00
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded trueadmin / admintrue credentials for an ISP.
- CVE-2021-27154Feb 10, 2021risk 0.00cvss —epss 0.00
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / G0R2U1P2ag credentials for an ISP.
- CVE-2021-27155Feb 10, 2021risk 0.00cvss —epss 0.00
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 3UJUh2VemEfUtesEchEC2d2e credentials for an ISP.
- CVE-2021-27156Feb 10, 2021risk 0.00cvss —epss 0.01
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains credentials for an ISP that equal the last part of the MAC address of the br0 interface.
- CVE-2021-27157Feb 10, 2021risk 0.00cvss —epss 0.01
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 888888 credentials for an ISP.
Page 1 of 3