ID

VAR-202102-1416


CVE

CVE-2021-27173


TITLE

FiberHome HG6245D  Authentication vulnerability in device

Trust: 0.8

sources: JVNDB: JVNDB-2021-003401

DESCRIPTION

An issue was discovered on FiberHome HG6245D devices through RP2613. There is a telnet?enable=0&key=calculated(BR0_MAC) backdoor API, without authentication, provided by the HTTP server. This will remove firewall rules and allow an attacker to reach the telnet server (used for the CLI). FiberHome HG6245D There is an authentication vulnerability in the device.Information may be tampered with. FiberHome HG6245D devices is a router of China FiberHome. Provide network connectivity function. An authorization issue vulnerability exists in FiberHome HG6245D devices, and an attacker can use the vulnerability to access the telnet server

Trust: 2.16

sources: NVD: CVE-2021-27173 // JVNDB: JVNDB-2021-003401 // CNVD: CNVD-2021-18375

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-18375

AFFECTED PRODUCTS

vendor:fiberhomemodel:hg6245dscope:lteversion:rp2613

Trust: 1.0

vendor:fiberhome groupmodel:hg6245dscope:lteversion:hg6245d firmware rp2613 until

Trust: 0.8

vendor:fiberhome groupmodel:hg6245dscope:eqversion: -

Trust: 0.8

vendor:fiberhomemodel:hg6245d devicesscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2021-18375 // JVNDB: JVNDB-2021-003401 // NVD: CVE-2021-27173

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-27173
value: HIGH

Trust: 1.0

NVD: CVE-2021-27173
value: HIGH

Trust: 0.8

CNVD: CNVD-2021-18375
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202102-1004
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2021-27173
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2021-18375
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2021-27173
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2021-27173
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2021-18375 // JVNDB: JVNDB-2021-003401 // CNNVD: CNNVD-202102-1004 // NVD: CVE-2021-27173

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:Improper authentication (CWE-287) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-003401 // NVD: CVE-2021-27173

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202102-1004

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202102-1004

PATCH

title:Top Pageurl:http://www.fiberhome.com/default.aspx

Trust: 0.8

title:Patch for FiberHome HG6245D devices authorization issue vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/253661

Trust: 0.6

sources: CNVD: CNVD-2021-18375 // JVNDB: JVNDB-2021-003401

EXTERNAL IDS

db:NVDid:CVE-2021-27173

Trust: 3.0

db:JVNDBid:JVNDB-2021-003401

Trust: 0.8

db:CNVDid:CNVD-2021-18375

Trust: 0.6

db:CNNVDid:CNNVD-202102-1004

Trust: 0.6

sources: CNVD: CNVD-2021-18375 // JVNDB: JVNDB-2021-003401 // CNNVD: CNNVD-202102-1004 // NVD: CVE-2021-27173

REFERENCES

url:https://pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.html#httpd-infoleak

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2021-27173

Trust: 1.4

url:https://pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.html#

Trust: 1.2

url:httpd-infoleak

Trust: 0.6

sources: CNVD: CNVD-2021-18375 // JVNDB: JVNDB-2021-003401 // CNNVD: CNNVD-202102-1004 // NVD: CVE-2021-27173

SOURCES

db:CNVDid:CNVD-2021-18375
db:JVNDBid:JVNDB-2021-003401
db:CNNVDid:CNNVD-202102-1004
db:NVDid:CVE-2021-27173

LAST UPDATE DATE

2024-11-23T22:05:14.720000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-18375date:2021-03-18T00:00:00
db:JVNDBid:JVNDB-2021-003401date:2021-10-26T07:20:00
db:CNNVDid:CNNVD-202102-1004date:2022-07-14T00:00:00
db:NVDid:CVE-2021-27173date:2024-11-21T05:57:28.530

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-18375date:2021-03-18T00:00:00
db:JVNDBid:JVNDB-2021-003401date:2021-10-26T00:00:00
db:CNNVDid:CNNVD-202102-1004date:2021-02-10T00:00:00
db:NVDid:CVE-2021-27173date:2021-02-10T19:15:15.183