An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains credentials for an ISP that equal the last part of the MAC address of the br0 interface.
References
Link | Resource |
---|---|
https://pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.html#httpd-hardcoded-credentials | Exploit Third Party Advisory |
https://pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.html#httpd-hardcoded-credentials | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 05:57
Type | Values Removed | Values Added |
---|---|---|
References | () https://pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.html#httpd-hardcoded-credentials - Exploit, Third Party Advisory |
Information
Published : 2021-02-10 19:15
Updated : 2024-11-21 05:57
NVD link : CVE-2021-27156
Mitre link : CVE-2021-27156
CVE.ORG link : CVE-2021-27156
JSON object : View
Products Affected
fiberhome
- hg6245d
- hg6245d_firmware
CWE
CWE-798
Use of Hard-coded Credentials