ID

VAR-202101-2008


TITLE

RCE vulnerability exists in FiberHome routers

Trust: 0.6

sources: CNVD: CNVD-2021-07061

DESCRIPTION

FiberHome, abbreviated as FiberHome, is a company headquartered in Wuhan, China Listed companies in the communications equipment manufacturing industry. FiberHome routers has an RCE vulnerability. Attackers can use this vulnerability to execute arbitrary commands on the target device with root privileges.

Trust: 0.6

sources: CNVD: CNVD-2021-07061

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-07061

AFFECTED PRODUCTS

vendor:fiber communicationmodel:an5506-02-bscope: - version: -

Trust: 0.6

vendor:fiber communicationmodel:hg6245dscope: - version: -

Trust: 0.6

vendor:fiber communicationmodel:an5506-04-fascope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2021-07061

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2021-07061
value: HIGH

Trust: 0.6

CNVD: CNVD-2021-07061
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2021-07061

PATCH

title:Patch for RCE vulnerability exists in FiberHome routersurl:https://www.cnvd.org.cn/patchinfo/show/245676

Trust: 0.6

sources: CNVD: CNVD-2021-07061

EXTERNAL IDS

db:CNVDid:CNVD-2021-07061

Trust: 0.6

sources: CNVD: CNVD-2021-07061

REFERENCES

url:https://pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.html#telnet

Trust: 0.6

sources: CNVD: CNVD-2021-07061

SOURCES

db:CNVDid:CNVD-2021-07061

LAST UPDATE DATE

2022-05-04T09:21:30.717000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-07061date:2021-01-28T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-07061date:2021-01-18T00:00:00