First published: Wed Feb 10 2021(Updated: )
An issue was discovered on FiberHome HG6245D devices through RP2613. There is a telnet?enable=0&key=calculated(BR0_MAC) backdoor API, without authentication, provided by the HTTP server. This will remove firewall rules and allow an attacker to reach the telnet server (used for the CLI).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fiberhome Hg6245d Firmware | <=rp2613 | |
FiberHome HG6245D |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27173 is a vulnerability found on FiberHome HG6245D devices through RP2613, allowing unauthorized access to the telnet server.
CVE-2021-27173 exploits a backdoor API that removes firewall rules and grants access to the telnet server without authentication.
No, authentication is not required to exploit CVE-2021-27173.
The severity of CVE-2021-27173 is high, with a CVSS score of 7.5.
Currently, there is no official fix for CVE-2021-27173. It is recommended to contact the vendor or apply any available patches or updates once they are released.