A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted from the SSID. The device generates default passwords using a deterministic algorithm that derives the router passphrase from the SSID, enabling an attacker who can observe the SSID to predict the default password without authentication or user interaction.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This 19-file repository is an educational multi-language proof of concept for CVE-2025-63353 affecting FiberHome HG6145F1 GPON ONTs with RP4423 firmware. It contains equivalent standalone PSK-derivation utilities in Python, Go, JavaScript, and C, plus a GitHub Actions workflow that builds/runs each implementation and verifies identical canonical results. Each tool validates a supplied SSID matching fh_<6 hex digits>, XORs its suffix with 0xFFFFFF, and returns wlan followed by the complemented six-digit hexadecimal value. The code performs no scanning, packet capture, network association, outbound connection, or exploitation beyond offline credential derivation. Documentation covers vulnerability mechanics, affected deployments, mitigations, references, related research, and disclosure history. No network URLs, IP addresses, domains, or service endpoints are contacted by the exploit code; the only target-identifying observable handled by it is the vulnerable device's broadcast SSID pattern.
This repository is a multi-language proof-of-concept and documentation set for CVE-2025-63353, a predictable default Wi-Fi PSK vulnerability affecting FiberHome HG6145F1 devices on firmware RP4423. The exploit capability is straightforward: given a broadcast SSID in the default format `fh_<6 hex>`, the code computes the factory WPA/WPA2 PSK as `wlan` plus the 24-bit XOR complement of the SSID suffix (`0xFFFFFF XOR hex_a`). This is credential derivation rather than memory corruption or code execution; it enables recovery of the default wireless password without capturing a handshake, brute forcing, or interacting with clients. Repository structure: the `poc/` directory contains four equivalent standalone implementations in Python, Go, JavaScript, and C. Each validates the SSID format, derives the PSK, and prints either the result or a message that the SSID is not in the vulnerable default format. The `.github/workflows/test.yml` workflow builds/runs all implementations and verifies they produce identical canonical outputs. The `docs/` directory provides extensive supporting material: vulnerability mechanics, affected deployments, mitigation guidance, disclosure timeline, references, and related research. There are no active network callbacks, exploit delivery stages, scanners, or post-exploitation payloads in the code. No IPs, domains, sockets, HTTP requests, registry keys, or remote services are contacted by the PoC itself. The primary fingerprintable target indicator is the SSID naming convention `fh_[0-9a-f]{6}` and the affected product identifiers in the documentation. Overall, this is a legitimate educational PoC for offline derivation of default Wi-Fi credentials from observable wireless identifiers.
This repository is a small proof-of-concept utility for CVE-2025-63353 affecting FiberHome HG6145F1 (RP4423) routers. It contains two files: a README describing the vulnerability, affected SSID/password patterns, usage, and mitigation guidance; and a single Python script, predictor.py, which implements the credential derivation logic. The exploit capability is limited to offline/default credential prediction: it takes a visible wireless SSID of the form 'fh_XXXXXX', parses the 6-hex-character suffix, converts it to an integer, subtracts it from 0xFFFFFF, and formats the result as a default Wi-Fi password 'wlanxxxxxx'. There is no network communication, scanning, brute force, exploitation of a service, or post-exploitation behavior. The attack vector is wireless because the attacker only needs to observe the broadcast SSID of a nearby target network. The script uses argparse, supports a verbose mode to display the arithmetic, and prints either the predicted password or an input validation error. Overall, this is a straightforward credential-prediction PoC rather than a weaponized exploit.
This repository provides a proof-of-concept exploit for CVE-2025-63353, a vulnerability in FiberHome GPON ONU HG6145F1 RP4423 devices. The vulnerability allows an attacker to predict the factory default Wi-Fi password from the SSID due to a deterministic password generation algorithm. The main code file, 'poc.go', is a Go program that scans for Wi-Fi networks using system tools ('nmcli', 'netsh', or 'airport'), identifies SSIDs matching the vulnerable pattern ('fh_<HEX_A>'), and calculates the corresponding default password ('wlan<HEX_B>') using the formula HEX_B = 0xFFFFFF - HEX_A. The results are saved to a file named 'passwords'. The repository includes a README with technical details, usage instructions, and references. The exploit is operational as a local tool for Wi-Fi reconnaissance and password recovery, but does not provide remote exploitation or post-exploitation payloads.
This repository documents a vulnerability (CVE-2025-63353) in the Fiberhome GPON ONU HG6145F1 RP4423 router, where the factory default Wi-Fi password can be predicted from the SSID due to a deterministic algorithm. The main file, 'CVE-2025-63353', describes the algorithm: the SSID is of the form 'fh_<HEX A>' and the default password is 'wlan<HEX B>', with HEX B calculated as 0xFFFFFF - HEX A. This allows an attacker within Wi-Fi range to derive the default WPA/WPA2 pre-shared key from the SSID, enabling unauthorized access. The repository contains a description of the vulnerability and the algorithm, but no executable code. The README summarizes the issue. The exploit is a proof-of-concept for information disclosure and does not include a detection script or weaponized payload.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.