CVE-2021-27156

An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains credentials for an ISP that equal the last part of the MAC address of the br0 interface.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:fiberhome:hg6245d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fiberhome:hg6245d:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:57

Type Values Removed Values Added
References () https://pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.html#httpd-hardcoded-credentials - Exploit, Third Party Advisory () https://pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.html#httpd-hardcoded-credentials - Exploit, Third Party Advisory

Information

Published : 2021-02-10 19:15

Updated : 2024-11-21 05:57


NVD link : CVE-2021-27156

Mitre link : CVE-2021-27156

CVE.ORG link : CVE-2021-27156


JSON object : View

Products Affected

fiberhome

  • hg6245d
  • hg6245d_firmware
CWE
CWE-798

Use of Hard-coded Credentials