Vulnerabilities
Vulnerable Software
Fiberhome:  >> Hg6245d  Security Vulnerabilities
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded trueadmin / admintrue credentials for an ISP.
CVSS Score
9.8
EPSS Score
0.003
Published
2021-02-10
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / G0R2U1P2ag credentials for an ISP.
CVSS Score
9.8
EPSS Score
0.007
Published
2021-02-10
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 3UJUh2VemEfUtesEchEC2d2e credentials for an ISP.
CVSS Score
9.8
EPSS Score
0.007
Published
2021-02-10
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains credentials for an ISP that equal the last part of the MAC address of the br0 interface.
CVSS Score
9.8
EPSS Score
0.007
Published
2021-02-10
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 888888 credentials for an ISP.
CVSS Score
9.8
EPSS Score
0.007
Published
2021-02-10
An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to extract information from the device without authentication by disabling JavaScript and visiting /info.asp.
CVSS Score
7.5
EPSS Score
0.001
Published
2021-02-10
An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to find passwords and authentication cookies stored in cleartext in the web.log HTTP logs.
CVSS Score
7.5
EPSS Score
0.0
Published
2021-02-10
An issue was discovered on FiberHome HG6245D devices through RP2613. Credentials in /fhconf/umconfig.txt are obfuscated via XOR with the hardcoded *j7a(L#yZ98sSd5HfSgGjMj8;Ss;d)(*&^#@$a2s0i3g key. (The webs binary has details on how XOR is used.)
CVSS Score
9.8
EPSS Score
0.002
Published
2021-02-10
An issue was discovered on FiberHome HG6245D devices through RP2613. The web management is done over HTTPS, using a hardcoded private key that has 0777 permissions.
CVSS Score
7.5
EPSS Score
0.001
Published
2021-02-10
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / user1234 credentials for an ISP.
CVSS Score
9.8
EPSS Score
0.007
Published
2021-02-10


Contact Us

Shodan ® - All rights reserved