CVE-2025-63353
A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted from the SSID. The device generates default passwords using a deterministic algorithm that derives the router passphrase from the SSID, enabling an attacker who can observe the SSID to predict the default password without authentication or user interaction.
- Affected products
- Fiberhome Gpon Onu Hg6145F1 Rp4423
- Fiberhome hg6145f1 Firmware
- = rp4423
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 1.3% (68th percentile)
- Weakness
- CWE-284
- NVD status
- Analyzed
- Published
- 2025-11-12
CVE-2025-63353 at NVD
6 known exploits for CVE-2025-63353
Proof-of-concept code and exploit modules indexed by Sploitus