📦 Hg6245d Firmware

by Fiberhome

🔍 What is Hg6245d Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-27171

CRITICAL CVSS 9.8 Feb 10, 2021

This vulnerability allows attackers to start a telnet daemon with root privileges on FiberHome HG6245D devices by using specific CLI commands. This enables complete device compromise and potential net...

CVE-2021-27177

CRITICAL CVSS 9.8 Feb 10, 2021

This vulnerability allows attackers to bypass authentication on FiberHome HG6245D devices by sending a specific decoded string to the telnet server. It affects FiberHome HG6245D optical network termin...

CVE-2021-27159

CRITICAL CVSS 9.8 Feb 10, 2021

FiberHome HG6245D devices contain hardcoded administrative credentials (useradmin/888888) in their web daemon, allowing unauthorized access to the device's management interface. This affects all devic...

CVE-2021-27161

CRITICAL CVSS 9.8 Feb 10, 2021

CVE-2021-27161 is a critical authentication bypass vulnerability affecting FiberHome HG6245D optical network terminals. The web management interface contains hardcoded admin credentials (admin/1234) t...

CVE-2021-27163

CRITICAL CVSS 9.8 Feb 10, 2021

CVE-2021-27163 is a critical authentication bypass vulnerability affecting FiberHome HG6245D optical network terminals. The devices contain hardcoded admin credentials (admin/tele1234) in their web in...

CVE-2021-27165

CRITICAL CVSS 9.8 Feb 10, 2021

CVE-2021-27165 is a critical authentication bypass vulnerability affecting FiberHome HG6245D optical network terminals. Attackers can exploit hardcoded telnet credentials (gpon/gpon) to gain unauthori...

CVE-2021-27167

CRITICAL CVSS 9.8 Feb 10, 2021

CVE-2021-27167 is a critical authentication bypass vulnerability affecting FiberHome HG6245D optical network terminals. The admin account has a hardcoded password consisting of only four hexadecimal c...

CVE-2021-27145

CRITICAL CVSS 9.8 Feb 10, 2021

FiberHome HG6245D devices contain hardcoded admin credentials (admin/lnadmin) in the web daemon, allowing attackers to gain administrative access. This affects all devices through firmware version RP2...

CVE-2021-27147

CRITICAL CVSS 9.8 Feb 10, 2021

FiberHome HG6245D devices contain hardcoded admin/admin credentials in their web daemon, allowing attackers to gain administrative access to the device. This affects all users of FiberHome HG6245D dev...

CVE-2021-27149

CRITICAL CVSS 9.8 Feb 10, 2021

CVE-2021-27149 is a critical authentication bypass vulnerability affecting FiberHome HG6245D devices. Attackers can use hardcoded admin credentials (adminpldt/z6dUABtl270qRxt7a2uGTiw) to gain administ...

CVE-2021-27151

CRITICAL CVSS 9.8 Feb 10, 2021

FiberHome HG6245D optical network terminal devices contain hardcoded root credentials (rootmet/m3tr0r00t) in their web daemon. This allows attackers to gain administrative access to the device's web i...

CVE-2021-27153

CRITICAL CVSS 9.8 Feb 10, 2021

CVE-2021-27153 is a critical authentication bypass vulnerability affecting FiberHome HG6245D optical network terminals. The web daemon contains hardcoded administrative credentials (trueadmin/admintru...

CVE-2021-27155

CRITICAL CVSS 9.8 Feb 10, 2021

CVE-2021-27155 is a critical authentication bypass vulnerability affecting FiberHome HG6245D optical network terminals. The web daemon contains hardcoded admin credentials (admin/3UJUh2VemEfUtesEchEC2...

CVE-2021-27157

CRITICAL CVSS 9.8 Feb 10, 2021

CVE-2021-27157 is a critical authentication bypass vulnerability affecting FiberHome HG6245D optical network terminals. The web daemon contains hardcoded admin credentials (admin/888888) that allow at...

CVE-2021-27141

CRITICAL CVSS 9.8 Feb 10, 2021

CVE-2021-27141 is a critical credential exposure vulnerability affecting FiberHome HG6245D devices. The credentials stored in /fhconf/umconfig.txt are obfuscated using a weak XOR algorithm with a hard...

CVE-2021-27143

CRITICAL CVSS 9.8 Feb 10, 2021

FiberHome HG6245D devices contain hardcoded credentials (user/user1234) in their web daemon, allowing attackers to gain administrative access to the device's web interface. This affects all FiberHome ...

CVE-2021-27173

HIGH CVSS 7.5 Feb 10, 2021

This vulnerability allows unauthenticated attackers to bypass firewall rules and enable telnet access on FiberHome HG6245D routers. It affects devices running firmware through RP2613, exposing them to...

CVE-2021-27175

HIGH CVSS 7.5 Feb 10, 2021

CVE-2021-27175 exposes WiFi passwords in cleartext within a configuration file on FiberHome HG6245D devices. This allows any local user or process to read sensitive credentials without authentication....

CVE-2021-27179

HIGH CVSS 7.5 Feb 10, 2021

This vulnerability allows remote attackers to crash the telnet daemon on FiberHome HG6245D devices by sending a specific malformed string. This causes a denial-of-service condition, disrupting telnet ...

CVE-2021-27139

HIGH CVSS 7.5 Feb 10, 2021

This vulnerability allows unauthenticated attackers to extract sensitive information from FiberHome HG6245D devices by disabling JavaScript and accessing the /info.asp endpoint. It affects FiberHome H...