Fiberhome manufactures a focused line of broadband access and residential gateway devices, including the HG6245D and AN5506 product families, that serve as customer premises equipment in service provider networks. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and cluster around weakness classes endemic to embedded networking gear: hard-coded credentials, cleartext sensitive-data storage, cross-site scripting, authentication bypasses, and code-injection flaws that can grant direct device compromise or administrative access. The narrow product portfolio masks a significant attack surface, since these devices are widely distributed at the network edge and often remain in service with minimal firmware update cycles. Defenders should prioritize inventory and isolation of affected gateway devices, particularly those exposed to untrusted networks, and treat credential reset and management-interface restrictions as mandatory hardening steps. Live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fiberhome over time
Signals from CVEs in this vendor scope (60 CVEs).
60 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14147CRITICAL An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to easily restore a router to its factory settings by simply brow | Sep 7, 2017 | 9.8 | 77 | NO | YES |
CVE-2017-16887CRITICAL The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services can re | Jan 12, 2018 | 9.8 | 59 | NO | YES |
CVE-2017-16885CRITICAL Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Changing Passwords, etc.) allows re | Jan 12, 2018 | 9.8 | 56 | NO | YES |
CVE-2017-15647HIGH On FiberHome routers, Directory Traversal exists in /cgi-bin/webproc via the getpage parameter in conjunction with a crafted var:page value. | Oct 19, 2017 | 7.5 | 56 | NO | YES |
CVE-2018-9248CRITICAL FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header. | Apr 4, 2018 | 9.8 | 51 | NO | YES |
CVE-2021-27148CRITICAL An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded telecomadmin / nE7jA%5m credentials for an ISP. | Feb 10, 2021 | 9.8 | 43 | NO | NO |
CVE-2021-27151CRITICAL An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded rootmet / m3tr0r00t credentials for an ISP. | Feb 10, 2021 | 9.8 | 42 | NO | NO |
CVE-2021-27149CRITICAL An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded adminpldt / z6dUABtl270qRxt7a2uGTiw credentials for an ISP. | Feb 10, 2021 | 9.8 | 42 | NO | NO |
CVE-2021-27145CRITICAL An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / lnadmin credentials for an ISP. | Feb 10, 2021 | 9.8 | 42 | NO | NO |
CVE-2021-27162CRITICAL An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / tattoo@home credentials for an ISP. | Feb 10, 2021 | 9.8 | 41 | NO | NO |
Signals from CVEs in this vendor scope (60 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fiberhome.
Media articles that mention a CVE ID that affects a product developed by Fiberhome — matched by CVE ID, not by vendor name.