Vendor CVEs
Fiberhome
All CVEs
63 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-14147 | Cri | 0.72 | 9.8 | 0.66 | Sep 7, 2017 | An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to easily restore a router to its factory settings by simply browsing to the link http://[Default-Router-IP]/restoreinfo.cgi & execute it. Due to improper… | ||
| CVE-2017-16887 | Cri | 0.70 | 9.8 | 0.37 | Jan 12, 2018 | The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services can result in disclosure of the WLAN key/password. | ||
| CVE-2017-16885 | Cri | 0.69 | 9.8 | 0.33 | Jan 12, 2018 | Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Changing Passwords, etc.) allows remote attackers to look for the information without authenticating. The information includes Version… | ||
| CVE-2018-9248 | Cri | 0.68 | 9.8 | 0.15 | Apr 4, 2018 | FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header. | ||
| CVE-2018-9249 | Cri | 0.64 | 9.8 | 0.06 | Apr 4, 2018 | FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass by ignoring the parent.location='login.html' JavaScript code in the response to an unauthenticated request. | ||
| CVE-2021-4464 | Cri | 0.61 | — | 0.02 | Nov 12, 2025 | FiberHome AN5506-04-FA firmware versions up to and including RP2631 and HG6245D prior to RP2602 contain a stack-based buffer overflow, as the HTTP service ('webs') fails to enforce maximum lengths for Cookie header values. When a cookie longer than 511 bytes is processed, a… | ||
| CVE-2017-16886 | Hig | 0.61 | 8.8 | 0.07 | Jan 12, 2018 | The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or password of the administrator of the portal. | ||
| CVE-2017-15647 | Hig | 0.54 | 7.5 | 0.27 | Oct 19, 2017 | On FiberHome routers, Directory Traversal exists in /cgi-bin/webproc via the getpage parameter in conjunction with a crafted var:page value. | ||
| CVE-2017-5544 | Med | 0.39 | 5.9 | 0.05 | Jan 23, 2017 | An issue was discovered on FiberHome Fengine S5800 switches V210R240. An unauthorized attacker can access the device's SSH service, using a password cracking tool to establish SSH connections quickly. This will trigger an increase in the SSH login timeout (each of the login… | ||
| CVE-2024-51432 | Med | 0.31 | 4.8 | 0.00 | Nov 1, 2024 | Cross Site Scripting vulnerability in FiberHome HG6544C RP2743 allows an attacker to execute arbitrary code via the SSID field in the WIFI Clients List not being sanitized | ||
| CVE-2019-9556 | 0.03 | — | 0.01 | Dec 31, 2019 | FiberHome an5506-04-f RP2669 devices have XSS. | |||
| CVE-2025-63353 | 0.00 | — | 0.01 | Nov 12, 2025 | A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted from the SSID. The device generates default passwords using a deterministic algorithm that derives the router passphrase from the… | |||
| CVE-2025-1616 | 0.00 | — | 0.09 | Feb 24, 2025 | A vulnerability, which was classified as critical, has been found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this issue is some unknown functionality of the component Diagnosis. The manipulation of the argument Destination Address leads to os command injection. The… | |||
| CVE-2025-1615 | 0.00 | — | 0.01 | Feb 24, 2025 | A vulnerability classified as problematic was found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this vulnerability is an unknown functionality of the component NAT Submenu. The manipulation of the argument Description leads to cross site scripting. The attack can be… | |||
| CVE-2025-1614 | 0.00 | — | 0.01 | Feb 24, 2025 | A vulnerability classified as problematic has been found in FiberHome AN5506-01A ONU GPON RP2511. Affected is an unknown function of the file /goform/portForwardingCfg of the component Port Forwarding Submenu. The manipulation of the argument pf_Description leads to cross site… | |||
| CVE-2025-1613 | 0.00 | — | 0.01 | Feb 24, 2025 | A vulnerability was found in FiberHome AN5506-01A ONU GPON RP2511. It has been rated as problematic. This issue affects some unknown processing of the file /goform/URL_filterCfg of the component URL Filtering Submenu. The manipulation of the argument url_IP leads to cross site… | |||
| CVE-2022-38814 | 0.00 | — | 0.03 | Sep 15, 2022 | A stored cross-site scripting (XSS) vulnerability in the auth_settings component of FiberHome AN5506-02-B vRP2521 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the sncfg_loid text field. | |||
| CVE-2022-36200 | 0.00 | — | 0.02 | Aug 29, 2022 | In FiberHome VDSL2 Modem HG150-Ub_V3.0, Credentials of Admin are submitted in URL, which can be logged/sniffed. | |||
| CVE-2021-41946 | 0.00 | — | 0.02 | May 18, 2022 | In FiberHome VDSL2 Modem HG150-Ub_V3.0, a stored cross-site scripting (XSS) vulnerability in Parental Control --> Access Time Restriction --> Username field, a user cannot delete the rule due to the XSS. | |||
| CVE-2021-42912 | 0.00 | — | 0.14 | Dec 16, 2021 | FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, bypassing the IP address field, and… | |||
| CVE-2021-27139 | 0.00 | — | 0.16 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to extract information from the device without authentication by disabling JavaScript and visiting /info.asp. | |||
| CVE-2021-27140 | 0.00 | — | 0.19 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to find passwords and authentication cookies stored in cleartext in the web.log HTTP logs. | |||
| CVE-2021-27141 | 0.00 | — | 0.16 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. Credentials in /fhconf/umconfig.txt are obfuscated via XOR with the hardcoded *j7a(L#yZ98sSd5HfSgGjMj8;Ss;d)(*&^#@$a2s0i3g key. (The webs binary has details on how XOR is used.) | |||
| CVE-2021-27142 | 0.00 | — | 0.16 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web management is done over HTTPS, using a hardcoded private key that has 0777 permissions. | |||
| CVE-2021-27143 | 0.00 | — | 0.16 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / user1234 credentials for an ISP. | |||
| CVE-2021-27144 | 0.00 | — | 0.22 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded f~i!b@e#r$h%o^m*esuperadmin / s(f)u_h+g|u credentials for an ISP. | |||
| CVE-2021-27145 | 0.00 | — | 0.24 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / lnadmin credentials for an ISP. | |||
| CVE-2021-27146 | 0.00 | — | 0.20 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / CUadmin credentials for an ISP. | |||
| CVE-2021-27147 | 0.00 | — | 0.17 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / admin credentials for an ISP. | |||
| CVE-2021-27148 | 0.00 | — | 0.24 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded telecomadmin / nE7jA%5m credentials for an ISP. | |||
| CVE-2021-27149 | 0.00 | — | 0.24 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded adminpldt / z6dUABtl270qRxt7a2uGTiw credentials for an ISP. | |||
| CVE-2021-27150 | 0.00 | — | 0.20 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded gestiontelebucaramanga / t3l3buc4r4m4ng42013 credentials for an ISP. | |||
| CVE-2021-27151 | 0.00 | — | 0.24 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded rootmet / m3tr0r00t credentials for an ISP. | |||
| CVE-2021-27152 | 0.00 | — | 0.24 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded awnfibre / fibre@dm!n credentials for an ISP. | |||
| CVE-2021-27153 | 0.00 | — | 0.20 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded trueadmin / admintrue credentials for an ISP. | |||
| CVE-2021-27154 | 0.00 | — | 0.20 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / G0R2U1P2ag credentials for an ISP. | |||
| CVE-2021-27155 | 0.00 | — | 0.20 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 3UJUh2VemEfUtesEchEC2d2e credentials for an ISP. | |||
| CVE-2021-27156 | 0.00 | — | 0.15 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains credentials for an ISP that equal the last part of the MAC address of the br0 interface. | |||
| CVE-2021-27157 | 0.00 | — | 0.15 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 888888 credentials for an ISP. | |||
| CVE-2021-27158 | 0.00 | — | 0.24 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded L1vt1m4eng / 888888 credentials for an ISP. | |||
| CVE-2021-27159 | 0.00 | — | 0.24 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded useradmin / 888888 credentials for an ISP. | |||
| CVE-2021-27160 | 0.00 | — | 0.17 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / 888888 credentials for an ISP. | |||
| CVE-2021-27161 | 0.00 | — | 0.17 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 1234 credentials for an ISP. | |||
| CVE-2021-27162 | 0.00 | — | 0.27 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / tattoo@home credentials for an ISP. | |||
| CVE-2021-27163 | 0.00 | — | 0.24 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / tele1234 credentials for an ISP. | |||
| CVE-2021-27164 | 0.00 | — | 0.24 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / aisadmin credentials for an ISP. | |||
| CVE-2021-27165 | 0.00 | — | 0.20 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The telnet daemon on port 23/tcp can be abused with the gpon/gpon credentials. | |||
| CVE-2021-27166 | 0.00 | — | 0.20 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. The password for the enable command is gpon. | |||
| CVE-2021-27167 | 0.00 | — | 0.15 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. There is a password of four hexadecimal characters for the admin account. These characters are generated in init_3bb_password in libci_adaptation_layer.so. | |||
| CVE-2021-27168 | 0.00 | — | 0.20 | Feb 10, 2021 | An issue was discovered on FiberHome HG6245D devices through RP2613. There is a 6GFJdY4aAuUKJjdtSn7d password for the rdsadmin account. |
- risk 0.72cvss 9.8epss 0.66
An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to easily restore a router to its factory settings by simply browsing to the link http://[Default-Router-IP]/restoreinfo.cgi & execute it. Due to improper…
- risk 0.70cvss 9.8epss 0.37
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services can result in disclosure of the WLAN key/password.
- risk 0.69cvss 9.8epss 0.33
Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Changing Passwords, etc.) allows remote attackers to look for the information without authenticating. The information includes Version…
- risk 0.68cvss 9.8epss 0.15
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.
- risk 0.64cvss 9.8epss 0.06
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass by ignoring the parent.location='login.html' JavaScript code in the response to an unauthenticated request.
- risk 0.61cvss —epss 0.02
FiberHome AN5506-04-FA firmware versions up to and including RP2631 and HG6245D prior to RP2602 contain a stack-based buffer overflow, as the HTTP service ('webs') fails to enforce maximum lengths for Cookie header values. When a cookie longer than 511 bytes is processed, a…
- risk 0.61cvss 8.8epss 0.07
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or password of the administrator of the portal.
- risk 0.54cvss 7.5epss 0.27
On FiberHome routers, Directory Traversal exists in /cgi-bin/webproc via the getpage parameter in conjunction with a crafted var:page value.
- risk 0.39cvss 5.9epss 0.05
An issue was discovered on FiberHome Fengine S5800 switches V210R240. An unauthorized attacker can access the device's SSH service, using a password cracking tool to establish SSH connections quickly. This will trigger an increase in the SSH login timeout (each of the login…
- risk 0.31cvss 4.8epss 0.00
Cross Site Scripting vulnerability in FiberHome HG6544C RP2743 allows an attacker to execute arbitrary code via the SSID field in the WIFI Clients List not being sanitized
- CVE-2019-9556Dec 31, 2019risk 0.03cvss —epss 0.01
FiberHome an5506-04-f RP2669 devices have XSS.
- CVE-2025-63353Nov 12, 2025risk 0.00cvss —epss 0.01
A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted from the SSID. The device generates default passwords using a deterministic algorithm that derives the router passphrase from the…
- CVE-2025-1616Feb 24, 2025risk 0.00cvss —epss 0.09
A vulnerability, which was classified as critical, has been found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this issue is some unknown functionality of the component Diagnosis. The manipulation of the argument Destination Address leads to os command injection. The…
- CVE-2025-1615Feb 24, 2025risk 0.00cvss —epss 0.01
A vulnerability classified as problematic was found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this vulnerability is an unknown functionality of the component NAT Submenu. The manipulation of the argument Description leads to cross site scripting. The attack can be…
- CVE-2025-1614Feb 24, 2025risk 0.00cvss —epss 0.01
A vulnerability classified as problematic has been found in FiberHome AN5506-01A ONU GPON RP2511. Affected is an unknown function of the file /goform/portForwardingCfg of the component Port Forwarding Submenu. The manipulation of the argument pf_Description leads to cross site…
- CVE-2025-1613Feb 24, 2025risk 0.00cvss —epss 0.01
A vulnerability was found in FiberHome AN5506-01A ONU GPON RP2511. It has been rated as problematic. This issue affects some unknown processing of the file /goform/URL_filterCfg of the component URL Filtering Submenu. The manipulation of the argument url_IP leads to cross site…
- CVE-2022-38814Sep 15, 2022risk 0.00cvss —epss 0.03
A stored cross-site scripting (XSS) vulnerability in the auth_settings component of FiberHome AN5506-02-B vRP2521 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the sncfg_loid text field.
- CVE-2022-36200Aug 29, 2022risk 0.00cvss —epss 0.02
In FiberHome VDSL2 Modem HG150-Ub_V3.0, Credentials of Admin are submitted in URL, which can be logged/sniffed.
- CVE-2021-41946May 18, 2022risk 0.00cvss —epss 0.02
In FiberHome VDSL2 Modem HG150-Ub_V3.0, a stored cross-site scripting (XSS) vulnerability in Parental Control --> Access Time Restriction --> Username field, a user cannot delete the rule due to the XSS.
- CVE-2021-42912Dec 16, 2021risk 0.00cvss —epss 0.14
FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, bypassing the IP address field, and…
- CVE-2021-27139Feb 10, 2021risk 0.00cvss —epss 0.16
An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to extract information from the device without authentication by disabling JavaScript and visiting /info.asp.
- CVE-2021-27140Feb 10, 2021risk 0.00cvss —epss 0.19
An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to find passwords and authentication cookies stored in cleartext in the web.log HTTP logs.
- CVE-2021-27141Feb 10, 2021risk 0.00cvss —epss 0.16
An issue was discovered on FiberHome HG6245D devices through RP2613. Credentials in /fhconf/umconfig.txt are obfuscated via XOR with the hardcoded *j7a(L#yZ98sSd5HfSgGjMj8;Ss;d)(*&^#@$a2s0i3g key. (The webs binary has details on how XOR is used.)
- CVE-2021-27142Feb 10, 2021risk 0.00cvss —epss 0.16
An issue was discovered on FiberHome HG6245D devices through RP2613. The web management is done over HTTPS, using a hardcoded private key that has 0777 permissions.
- CVE-2021-27143Feb 10, 2021risk 0.00cvss —epss 0.16
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / user1234 credentials for an ISP.
- CVE-2021-27144Feb 10, 2021risk 0.00cvss —epss 0.22
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded f~i!b@e#r$h%o^m*esuperadmin / s(f)u_h+g|u credentials for an ISP.
- CVE-2021-27145Feb 10, 2021risk 0.00cvss —epss 0.24
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / lnadmin credentials for an ISP.
- CVE-2021-27146Feb 10, 2021risk 0.00cvss —epss 0.20
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / CUadmin credentials for an ISP.
- CVE-2021-27147Feb 10, 2021risk 0.00cvss —epss 0.17
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / admin credentials for an ISP.
- CVE-2021-27148Feb 10, 2021risk 0.00cvss —epss 0.24
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded telecomadmin / nE7jA%5m credentials for an ISP.
- CVE-2021-27149Feb 10, 2021risk 0.00cvss —epss 0.24
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded adminpldt / z6dUABtl270qRxt7a2uGTiw credentials for an ISP.
- CVE-2021-27150Feb 10, 2021risk 0.00cvss —epss 0.20
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded gestiontelebucaramanga / t3l3buc4r4m4ng42013 credentials for an ISP.
- CVE-2021-27151Feb 10, 2021risk 0.00cvss —epss 0.24
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded rootmet / m3tr0r00t credentials for an ISP.
- CVE-2021-27152Feb 10, 2021risk 0.00cvss —epss 0.24
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded awnfibre / fibre@dm!n credentials for an ISP.
- CVE-2021-27153Feb 10, 2021risk 0.00cvss —epss 0.20
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded trueadmin / admintrue credentials for an ISP.
- CVE-2021-27154Feb 10, 2021risk 0.00cvss —epss 0.20
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / G0R2U1P2ag credentials for an ISP.
- CVE-2021-27155Feb 10, 2021risk 0.00cvss —epss 0.20
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 3UJUh2VemEfUtesEchEC2d2e credentials for an ISP.
- CVE-2021-27156Feb 10, 2021risk 0.00cvss —epss 0.15
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains credentials for an ISP that equal the last part of the MAC address of the br0 interface.
- CVE-2021-27157Feb 10, 2021risk 0.00cvss —epss 0.15
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 888888 credentials for an ISP.
- CVE-2021-27158Feb 10, 2021risk 0.00cvss —epss 0.24
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded L1vt1m4eng / 888888 credentials for an ISP.
- CVE-2021-27159Feb 10, 2021risk 0.00cvss —epss 0.24
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded useradmin / 888888 credentials for an ISP.
- CVE-2021-27160Feb 10, 2021risk 0.00cvss —epss 0.17
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / 888888 credentials for an ISP.
- CVE-2021-27161Feb 10, 2021risk 0.00cvss —epss 0.17
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 1234 credentials for an ISP.
- CVE-2021-27162Feb 10, 2021risk 0.00cvss —epss 0.27
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / tattoo@home credentials for an ISP.
- CVE-2021-27163Feb 10, 2021risk 0.00cvss —epss 0.24
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / tele1234 credentials for an ISP.
- CVE-2021-27164Feb 10, 2021risk 0.00cvss —epss 0.24
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / aisadmin credentials for an ISP.
- CVE-2021-27165Feb 10, 2021risk 0.00cvss —epss 0.20
An issue was discovered on FiberHome HG6245D devices through RP2613. The telnet daemon on port 23/tcp can be abused with the gpon/gpon credentials.
- CVE-2021-27166Feb 10, 2021risk 0.00cvss —epss 0.20
An issue was discovered on FiberHome HG6245D devices through RP2613. The password for the enable command is gpon.
- CVE-2021-27167Feb 10, 2021risk 0.00cvss —epss 0.15
An issue was discovered on FiberHome HG6245D devices through RP2613. There is a password of four hexadecimal characters for the admin account. These characters are generated in init_3bb_password in libci_adaptation_layer.so.
- CVE-2021-27168Feb 10, 2021risk 0.00cvss —epss 0.20
An issue was discovered on FiberHome HG6245D devices through RP2613. There is a 6GFJdY4aAuUKJjdtSn7d password for the rdsadmin account.
Page 1 of 2