← Vulnerability feed

Vulnerability record · CVE-2021-27167 · published 10 February 2021

CVE-2021-27167: Fiberhome hg6245d firmware hard-coded credentials vulnerability

Fiberhome · Hg6245d Firmware

An issue was discovered on FiberHome HG6245D devices through RP2613. There is a password of four hexadecimal characters for the admin account. These characters are generated in init_3bb_password in libci_adaptation_layer.so.

9.8 CVSS 3.1 Critical EPSS 15% · top 3.5% CWE-798 · Hard-coded credentials
9.8CVSS 3.1 base score, v2 5.0
15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered on FiberHome HG6245D devices through RP2613. There is a password of four hexadecimal characters for the admin account. These characters are generated in init_3bb_password in libci_adaptation_layer.so.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-27167 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-27171Fiberhome hg6245d firmware out-of-bounds write vulnerabilityAn issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to start a Linux telnetd as root on port 26/tcp by using the CLI …EPSS 18%9.8CVE-2021-27172Fiberhome hg6245d firmware hard-coded credentials vulnerabilityAn issue was discovered on FiberHome HG6245D devices through RP2613. A hardcoded GEPON password for root is defined inside /etc/init.d/system-config.…EPSS 20%9.8CVE-2021-27177Fiberhome hg6245d firmware incorrect authorization vulnerabilityAn issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to bypass authentication by sending the decoded value of the Ggpo…EPSS 20%9.8CVE-2021-27158Fiberhome hg6245d firmware hard-coded credentials vulnerabilityAn issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded L1vt1m4eng / 888888 credentials for an ISP.EPSS 24%9.8CVE-2021-27159Fiberhome hg6245d firmware hard-coded credentials vulnerabilityAn issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded useradmin / 888888 credentials for an ISP.EPSS 24%9.8CVE-2021-27160Fiberhome hg6245d firmware hard-coded credentials vulnerabilityAn issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / 888888 credentials for an ISP.EPSS 17%9.8CVE-2021-27161Fiberhome hg6245d firmware hard-coded credentials vulnerabilityAn issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 1234 credentials for an ISP.EPSS 17%9.8CVE-2021-27162Fiberhome hg6245d firmware hard-coded credentials vulnerabilityAn issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / tattoo@home credentials for an ISP.EPSS 27%

Source: NIST National Vulnerability Database (record CVE-2021-27167), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.