VulnerabilityModified
CVE-2021-27179
It is possible to crash the telnet daemon by sending a certain 0a 65 6e 61 62 6c 65 0a 02 0a 1a 0a string.
HIGH 7.5EPSS 13.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to crash the telnet daemon by sending a certain 0a 65 6e 61 62 6c 65 0a 02 0a 1a 0a string.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 13.93% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- fiberhome/hg6245d firmware
- Source
- cve@mitre.org
References
- https://pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.html#telnet-cli-dosExploit, Third Party Advisory
- https://pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.html#telnet-cli-dosExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.