First published: Wed Feb 10 2021(Updated: )
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded trueadmin / admintrue credentials for an ISP.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fiberhome Hg6245d Firmware | <=rp2613 | |
FiberHome HG6245D |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27153 is a vulnerability found in FiberHome HG6245D devices through RP2613, where the web daemon contains hardcoded credentials for the ISP admin account.
CVE-2021-27153 has a severity rating of 9.8 (Critical).
The affected software versions are Fiberhome HG6245D Firmware up to and including RP2613.
To fix CVE-2021-27153, FiberHome HG6245D device owners should contact FiberHome for a firmware update that addresses the hardcoded credentials issue.
More information about CVE-2021-27153 can be found at the following reference: https://pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.html#httpd-hardcoded-credentials