Sale of 0-day exploits for FiberHome and GL.iNet networking equipment
Dark Web2026-09-24, 11:17
For informational purposes only.
Vulnerability Type: RCE / Authentication Bypass / Local Privilege Escalation / Information Disclosure
Products: GL.iNet GL-BE9300 (Flint 3), FiberHome routers/ONT
Affected versions: GL.iNet firmware 4.10.0; FiberHome — unknown
The author claims to have discovered a set of vulnerabilities in FiberHome and GL.iNet networking equipment while analyzing firmware using AI, and then verified the results manually.
In the case of GL.iNet, the device in question is presumably the GL-BE9300 (Flint 3) running firmware 4.10.0. This is a current tri-band Wi-Fi 7 router designed for home and small office use.
The published PoC demonstrates several attack chains. Via SSH, the author demonstrates obtaining a root shell without a password and full RCE. The second method involves connecting to the Wi-Fi network, followed by logging in via SSH as root. Through the Web UI, the researchers report bypassing authentication with an empty root password: while arbitrary commands cannot be executed this way, system operations such as reboot, factory reset, and service restart are available.
The second part of the research concerns FiberHome—a manufacturer of GPON/ONT equipment that operators install for subscribers in FTTH networks. The company officially positions its GPON ONTs for home and SOHO fiber connections.
Regarding FiberHome, the researcher reports several independent issues: a command execution mechanism, an additional vulnerability in the /boa/frm web interface handler and related CmdType, as well as an authentication issue—the “fiberhome” key used for HMAC, he claims, is extracted directly from the client-side JavaScript. The author has not publicly disclosed the exact models, firmware versions, or exploitation details.
Separately, the author claims that there are approximately 1.1 million potentially accessible devices on the open internet.
Vendors
Products