---
id: CVE-2021-42912
title: >-
  FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection
  vulnerability
summary: >-
  FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection
  vulnerability. This vulnerability allows the attacker, once logged in, to send
  commands to the operating system as the root user via the ping diagnostic
  tool, b…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: fiberhome
product: an5506-01-a_firmware
affected:
  - an5506-01-a_firmware = rp0509
  - an5506-01-b_firmware = rp2610
  - an5506-02-b_firmware = rp2520
  - an5506-02-b_firmware = rp2521
  - an5506-02-b_firmware = rp2603
  - an5506-04-b_firmware = rp2510
  - an5506-04-f_firmware = rp2617
  - aan5506-04-g2g_firmware = rp2560
published: '2021-12-16'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-42912'
references:
  - url: >-
      https://medium.com/@windsormoreira/fiberhome-an5506-os-command-injection-cve-2021-42912-10b64fd10ce2
    label: cve@mitre.org
  - url: 'http://fiberhome.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://onu.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://medium.com/%40windsormoreira/fiberhome-an5506-os-command-injection-cve-2021-42912-10b64fd10ce2
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.10087
epssPercentile: 0.95469
ingestedAt: '2026-07-06T01:08:17.077Z'
---

## Overview

FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, bypassing the IP address field, and concatenating OS commands with a semicolon.

## Affected

- `an5506-01-a_firmware = rp0509`
- `an5506-01-b_firmware = rp2610`
- `an5506-02-b_firmware = rp2520`
- `an5506-02-b_firmware = rp2521`
- `an5506-02-b_firmware = rp2603`
- `an5506-04-b_firmware = rp2510`
- `an5506-04-f_firmware = rp2617`
- `aan5506-04-g2g_firmware = rp2560`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
