Vulnerability index

Browse CVEs

57 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Hg6145f1 Firmware CRITICAL 9.8
CVE-2025-63353

A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted fr…

Mitigation only
Fix from $2,300 2025-11-12
An5506 01a Firmware CRITICAL 9.8
CVE-2025-1616EPSS 8%

A vulnerability, which was classified as critical, has been found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this issue is some unknown fun…

Mitigation only
Fix from $2,300 2025-02-24
An5506 02 B Firmware MEDIUM 5.4
CVE-2022-38814

A stored cross-site scripting (XSS) vulnerability in the auth_settings component of FiberHome AN5506-02-B vRP2521 allows attackers to execute arbitra…

No fix yet
Fix from $1,600 2022-09-15
Hg150 Ub Firmware HIGH 7.5
CVE-2022-36200

In FiberHome VDSL2 Modem HG150-Ub_V3.0, Credentials of Admin are submitted in URL, which can be logged/sniffed.

No fix yet
Fix from $1,950 2022-08-29
Hg150 Ub Firmware MEDIUM 5.4
CVE-2021-41946

In FiberHome VDSL2 Modem HG150-Ub_V3.0, a stored cross-site scripting (XSS) vulnerability in Parental Control --> Access Time Restriction --> Usernam…

No fix yet
Fix from $1,600 2022-05-18
An5506 01 A Firmware HIGH 8.8
CVE-2021-42912EPSS 10%

FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, t…

Mitigation only
Fix from $1,950 2021-12-16
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27171EPSS 18%

An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to start a Linux telnetd as root on port 26/tcp by using the CLI …

No fix yet
Fix from $2,300 2021-02-10
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27172EPSS 20%

An issue was discovered on FiberHome HG6245D devices through RP2613. A hardcoded GEPON password for root is defined inside /etc/init.d/system-config.…

No fix yet
Fix from $2,300 2021-02-10
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27177EPSS 20%

An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to bypass authentication by sending the decoded value of the Ggpo…

No fix yet
Fix from $2,300 2021-02-10
Hg6245d Firmware HIGH 7.5
CVE-2021-27173EPSS 13%

An issue was discovered on FiberHome HG6245D devices through RP2613. There is a telnet?enable=0&key=calculated(BR0_MAC) backdoor API, without authent…

No fix yet
Fix from $1,950 2021-02-10
Hg6245d Firmware HIGH 7.5
CVE-2021-27174EPSS 19%

An issue was discovered on FiberHome HG6245D devices through RP2613. wifi_custom.cfg has cleartext passwords and 0644 permissions.

No fix yet
Fix from $1,950 2021-02-10
Hg6245d Firmware HIGH 7.5
CVE-2021-27175EPSS 18%

An issue was discovered on FiberHome HG6245D devices through RP2613. wifictl_2g.cfg has cleartext passwords and 0644 permissions.

No fix yet
Fix from $1,950 2021-02-10
Hg6245d Firmware HIGH 7.5
CVE-2021-27176EPSS 19%

An issue was discovered on FiberHome HG6245D devices through RP2613. wifictl_5g.cfg has cleartext passwords and 0644 permissions.

No fix yet
Fix from $1,950 2021-02-10
Hg6245d Firmware HIGH 7.5
CVE-2021-27178EPSS 18%

An issue was discovered on FiberHome HG6245D devices through RP2613. Some passwords are stored in cleartext in nvram.

No fix yet
Fix from $1,950 2021-02-10
Hg6245d Firmware HIGH 7.5
CVE-2021-27179EPSS 14%

An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to crash the telnet daemon by sending a certain 0a 65 6e 61 62 6c…

No fix yet
Fix from $1,950 2021-02-10
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27158EPSS 24%

An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded L1vt1m4eng / 888888 credentials for an ISP.

No fix yet
Fix from $2,300 2021-02-10
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27159EPSS 24%

An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded useradmin / 888888 credentials for an ISP.

No fix yet
Fix from $2,300 2021-02-10
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27160EPSS 17%

An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / 888888 credentials for an ISP.

No fix yet
Fix from $2,300 2021-02-10
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27161EPSS 17%

An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 1234 credentials for an ISP.

No fix yet
Fix from $2,300 2021-02-10
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27162EPSS 27%

An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / tattoo@home credentials for an ISP.

No fix yet
Fix from $2,300 2021-02-10
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27163EPSS 24%

An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / tele1234 credentials for an ISP.

No fix yet
Fix from $2,300 2021-02-10
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27164EPSS 24%

An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / aisadmin credentials for an ISP.

No fix yet
Fix from $2,300 2021-02-10
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27165EPSS 20%

An issue was discovered on FiberHome HG6245D devices through RP2613. The telnet daemon on port 23/tcp can be abused with the gpon/gpon credentials.

No fix yet
Fix from $2,300 2021-02-10
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27166EPSS 20%

An issue was discovered on FiberHome HG6245D devices through RP2613. The password for the enable command is gpon.

No fix yet
Fix from $2,300 2021-02-10
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27167EPSS 15%

An issue was discovered on FiberHome HG6245D devices through RP2613. There is a password of four hexadecimal characters for the admin account. These …

No fix yet
Fix from $2,300 2021-02-10
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27168EPSS 20%

An issue was discovered on FiberHome HG6245D devices through RP2613. There is a 6GFJdY4aAuUKJjdtSn7d password for the rdsadmin account.

No fix yet
Fix from $2,300 2021-02-10
An5506 04 Fa Firmware CRITICAL 9.8
CVE-2021-27169EPSS 20%

An issue was discovered on FiberHome AN5506-04-FA devices with firmware RP2631. There is a gepon password for the gepon account.

No fix yet
Fix from $2,300 2021-02-10
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27170EPSS 16%

An issue was discovered on FiberHome HG6245D devices through RP2613. By default, there are no firewall rules for IPv6 connectivity, exposing the inte…

No fix yet
Fix from $2,300 2021-02-10
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27144EPSS 22%

An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded f~i!b@e#r$h%o^m*esuperadmin / s(f)u_h+g|u …

No fix yet
Fix from $2,300 2021-02-10
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27145EPSS 24%

An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / lnadmin credentials for an ISP.

No fix yet
Fix from $2,300 2021-02-10