CVE-2021-27156

An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains credentials for an ISP that equal the last part of the MAC address of the br0 interface.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:fiberhome:hg6245d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fiberhome:hg6245d:-:*:*:*:*:*:*:*

History

11 Feb 2021, 00:52

Type Values Removed Values Added
References (MISC) https://pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.html#httpd-hardcoded-credentials - (MISC) https://pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.html#httpd-hardcoded-credentials - Exploit, Third Party Advisory
CPE cpe:2.3:o:fiberhome:hg6245d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fiberhome:hg6245d:-:*:*:*:*:*:*:*
CWE CWE-798
CVSS v2 : unknown
v3 : unknown
v2 : 7.5
v3 : 9.8

10 Feb 2021, 19:57

Type Values Removed Values Added
New CVE

Information

Published : 2021-02-10 19:15

Updated : 2023-12-10 13:41


NVD link : CVE-2021-27156

Mitre link : CVE-2021-27156

CVE.ORG link : CVE-2021-27156


JSON object : View

Products Affected

fiberhome

  • hg6245d_firmware
  • hg6245d
CWE
CWE-798

Use of Hard-coded Credentials