XOR Obfuscation Issue in FiberHome HG6245D Devices
CVE-2021-27141
9.8CRITICAL
What is CVE-2021-27141?
An obfuscation issue has been identified within FiberHome HG6245D devices. The credentials stored in the configuration file /fhconf/umconfig.txt are obfuscated using a simplistic XOR technique with a hardcoded key. This security flaw allows malicious actors to potentially decrypt sensitive information, posing a significant risk to user security and data integrity. The method of obfuscation employed lacks adequate complexity, making it vulnerable to reverse engineering, allowing unauthorized access to device configurations.