Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

41 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)20%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / G0R2U1P2ag credentials for an ISP.
ModificadaCrítica (9.8)20%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded trueadmin / admintrue credentials for an ISP.
ModificadaCrítica (9.8)23%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded awnfibre / fibre@dm!n credentials for an ISP.
ModificadaCrítica (9.8)23%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded rootmet / m3tr0r00t credentials for an ISP.
ModificadaCrítica (9.8)20%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded gestiontelebucaramanga / t3l3buc4r4m4ng42013 credentials for an ISP.
ModificadaCrítica (9.8)24%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded adminpldt / z6dUABtl270qRxt7a2uGTiw credentials for an ISP.
ModificadaCrítica (9.8)24%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded telecomadmin / nE7jA%5m credentials for an ISP.
ModificadaCrítica (9.8)17%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / admin credentials for an ISP.
ModificadaCrítica (9.8)20%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / CUadmin credentials for an ISP.
ModificadaCrítica (9.8)24%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / lnadmin credentials for an ISP.
ModificadaCrítica (9.8)21%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded f~i!b@e#r$h%o^m*esuperadmin / s(f)u_h+g|u credentials for an ISP.
ModificadaCrítica (9.8)16%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / user1234 credentials for an ISP.
ModificadaAlta (7.5)16%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web management is done over HTTPS, using a hardcoded private key that has 0777 permissions.
ModificadaCrítica (9.8)16%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. Credentials in /fhconf/umconfig.txt are obfuscated via XOR with the hardcoded *j7a(L#yZ98sSd5HfSgGjMj8;Ss;d)(*&^#@$a2s0i3g key. (The webs binary has details on how XOR is used.)
ModificadaAlta (7.5)19%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to find passwords and authentication cookies stored in cleartext in the web.log HTTP logs.
ModificadaAlta (7.5)16%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to extract information from the device without authentication by disabling JavaScript and visiting /info.asp.
Orbitaley — Vulnerabilidades