Hardcoded Credentials Vulnerability in FiberHome HG6245D Devices
CVE-2021-27161
9.8CRITICAL
Summary
A security flaw has been identified in the FiberHome HG6245D devices whereby the web daemon employs hardcoded administrative credentials. These default credentials, 'admin' with the password '1234', are exposed by an ISP, leading to significant security risks. Attackers can exploit this weakness to gain unauthorized access to the device, potentially allowing them to manipulate configurations or compromise user data.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved