An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains credentials for an ISP that equal the last part of the MAC address of the br0 interface.
References
Link | Resource |
---|---|
https://pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.html#httpd-hardcoded-credentials | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2021-02-10 11:15
Updated : 2021-02-10 16:52
NVD link : CVE-2021-27156
Mitre link : CVE-2021-27156
JSON object : View
CWE
CWE-798
Use of Hard-coded Credentials
Products Affected
fiberhome
- hg6245d
- hg6245d_firmware