FiberHome GPON ONU HG6145F1 Wi-Fi Password Prediction Vulnerability

Vulnerability

A vulnerability exists in the FiberHome GPON ONU model HG6145F1, specifically in the RP4423 version. This issue allows the device's factory default Wi-Fi password, which is the WPA/WPA2 pre-shared key, to be predicted based on the SSID. The router generates default passwords using a deterministic algorithm that links the SSID to the password. As a result, an attacker who can see the SSID can forecast the default password without needing authentication or user interaction.

Impact

Exploitation of this vulnerability allows for unauthorized access to the Wi-Fi network, potentially leading to data theft and surveillance, as well as unauthorized access to devices connected to the network.

Reproduction

The vulnerability can be reproduced by observing the SSID of a FiberHome GPON ONU HG6145F1 router. The default Wi-Fi password can be predicted by applying a simple mathematical operation that involves converting parts of the SSID and the password into hexadecimal and decimal values. This relationship can be used to derive the password from the SSID.

Remediation

Users are advised to change the default SSID and password, disable Wi-Fi Protected Setup (WPS), update the router firmware, and if possible, replace ISP-provided routers.

Added: Nov 12, 2025, 4:20 PM
Updated: Nov 12, 2025, 4:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.0
exploitability
6.2
remediation
0.0
relevance
1.1
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.