Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Fiberhome

First CVE: Jan 23, 2017Active for: 9 yearsTotal CVEs: 60
58.1
VTI Score
TOP TARGET

Fiberhome manufactures a focused line of broadband access and residential gateway devices, including the HG6245D and AN5506 product families, that serve as customer premises equipment in service provider networks. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and cluster around weakness classes endemic to embedded networking gear: hard-coded credentials, cleartext sensitive-data storage, cross-site scripting, authentication bypasses, and code-injection flaws that can grant direct device compromise or administrative access. The narrow product portfolio masks a significant attack surface, since these devices are widely distributed at the network edge and often remain in service with minimal firmware update cycles. Defenders should prioritize inventory and isolation of affected gateway devices, particularly those exposed to untrusted networks, and treat credential reset and management-interface restrictions as mandatory hardening steps. Live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
60
Total CVEs
More Total CVEs than 99% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
8.8
Avg CVSS Score
Higher Avg CVSS Score than 87% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Fiberhome over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 23, 2017
9 years ago
Most Recent CVE
Nov 12, 2025
254 days ago

Products(37 total)

Top CVEs

Signals from CVEs in this vendor scope (60 CVEs).

60 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-14147CRITICAL
An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to easily restore a router to its factory settings by simply brow
Sep 7, 20179.877NOYES
CVE-2017-16887CRITICAL
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services can re
Jan 12, 20189.859NOYES
CVE-2017-16885CRITICAL
Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Changing Passwords, etc.) allows re
Jan 12, 20189.856NOYES
CVE-2017-15647HIGH
On FiberHome routers, Directory Traversal exists in /cgi-bin/webproc via the getpage parameter in conjunction with a crafted var:page value.
Oct 19, 20177.556NOYES
CVE-2018-9248CRITICAL
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.
Apr 4, 20189.851NOYES
CVE-2021-27148CRITICAL
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded telecomadmin / nE7jA%5m credentials for an ISP.
Feb 10, 20219.843NONO
CVE-2021-27151CRITICAL
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded rootmet / m3tr0r00t credentials for an ISP.
Feb 10, 20219.842NONO
CVE-2021-27149CRITICAL
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded adminpldt / z6dUABtl270qRxt7a2uGTiw credentials for an ISP.
Feb 10, 20219.842NONO
CVE-2021-27145CRITICAL
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / lnadmin credentials for an ISP.
Feb 10, 20219.842NONO
CVE-2021-27162CRITICAL
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / tattoo@home credentials for an ISP.
Feb 10, 20219.841NONO
View all 60 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products60 CVEs
10%
25%
65%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network60 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low59 (98.3%)
High1 (1.7%)
Unknown0 (0.0%)
User Interaction
None54 (90.0%)
Unknown0 (0.0%)
Required6 (10.0%)
Privileges Required
Low4 (6.7%)
High3 (5.0%)
None53 (88.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (60 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.7% of CVEs· 95th percentile
ExploitDB
6 CVEs
10.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Fiberhome.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Fiberhome — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Fiberhome's Products

View all 2 CNAs →

Top CWEs