CVE-2021-27170

An issue was discovered on FiberHome HG6245D devices through RP2613. By default, there are no firewall rules for IPv6 connectivity, exposing the internal management interfaces to the Internet.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:fiberhome:hg6245d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fiberhome:hg6245d:-:*:*:*:*:*:*:*

History

12 Feb 2021, 01:00

Type Values Removed Values Added
CWE CWE-922
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 9.8
CPE cpe:2.3:o:fiberhome:hg6245d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fiberhome:hg6245d:-:*:*:*:*:*:*:*
References (MISC) https://pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.html#insecure-ipv6 - (MISC) https://pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.html#insecure-ipv6 - Exploit, Third Party Advisory

10 Feb 2021, 19:57

Type Values Removed Values Added
New CVE

Information

Published : 2021-02-10 19:15

Updated : 2023-12-10 13:41


NVD link : CVE-2021-27170

Mitre link : CVE-2021-27170

CVE.ORG link : CVE-2021-27170


JSON object : View

Products Affected

fiberhome

  • hg6245d_firmware
  • hg6245d
CWE
CWE-922

Insecure Storage of Sensitive Information