Jun 26, 2019

PLDT Fibr ONU AN5506-04-FA RP2631 Super Admin

Oh Well!!! Today when I woke up something strange happen to my PLDT Fibr Optical Network Unit (ONU) AN5506-04-FA as I have been expecting the so called RP2631 firmware update will be enforce and will be force to whether I like it or you don't, it will and will really be patched including YOURS and MINE.

What is new to the PLDT Fibr ONU firmware update RP2631? The Giant Telco ISP likes and wants their AN5506-04-FA/T ONU will serve just like a sitting duck as much as possible it would be a media converter only, why because 171 is fed up already about your calls you are so annoying!!!

Here's the quick and simple summary that PLDT wants to their all-in-one device aka the Fiberhome AN5506-04-FA/T Optical Network Unit and likewise a wireless access point (WAP) router built with two WiFi frequency such as 2.4GHz and 5GHz, it is also equip with two FXS for POTS but in addition you can insert your USB media device too. SAMBA and FTP server is great on this ONU device if were not restricted on the custom PLDT Fibr firmware.

Let see on the Graphical User Interface (GUI), the AN5506-04-FA/T RP2627 firmware downward you can login on the insecure port 80 via HTTP but not here in RP2631 HTTPS is being enforce while port 443 is use.


Next let see if the http://192.168.1.1/info.asp is still vulnerable without using any credential to login to the Fiberhome AN5506-04-FA/T ONU device.


Good patching the firmware already updated, its no longer accessible unlike before you can see the details without going to login to the PLDT Fibr ONU device. Thanks for that effort!


Now the exciting one, lets login to the PLDT Fibr AN5506-04-FA/T firmware RP2631. The username "admin" with the password "1234" for ordinary user account is no longer accepted its now being omitted. So what about the account for the username "adminpldt" with the password "6GFJdY4aAuUKJjdtSn7dC2x" will it be still accessible? And another thing is what happen to the Super Admin Account the username "fiberhomesuperadmin" with the password "sfuhgu" will it still work here on the new firmware updates.


As I have tested and verified all three previous username and password for PLDT Fibr ONU device AN5506-04-FA/T is no longer valid such as username "admin" password "1234", username "adminpldt" password "6GFJdY4aAuUKJjdtSn7dC2x" and username "fiberhomesuperadmin" password "sfuhgu" after the updates. Forget about your custom username and password that you have saved its totally gone.

When I dive and go into the shell I see two account credentials is allowed to get in,  only the Administrator account and the Super Admin account that the PLDT Fibr ONU is giving the permission to do login into the device nothing else can access the Graphical User Interface as for moment in time for my ONU. 

To access the PLDT AN5506-04-FA/T RP2631 firmware GUI Administrator account you have to point your web browser to https:/192.168.1.1/fh but you have to login first as Super Admin and enable the Web Admin Switch from the Management>> Device Mangement>> Debug Switch. Once enabled the Web Admin Switch logout and login again as Administrator account you can now again enjoy the privilege that have been enjoyed before of your ONU PLDT device.


Seen the above screenshot? Yes, that is the new PLDT Fibr ONU AN5506-04-FA/T RP2631 firmware update for the Super Admin account username "f~i!b@e#r$h%o^m*esuperadmin" its a 27 character so be careful on typo error its case sensitive. For Administrator account username still its "adminpldt" the password is no longer "1234567890" nor "0123456789" and certainly not "6GFJdY4aAuUKJjdtSn7dC2x" they changed it already. I am still planning to make a tutorial for the firmware downgrade from RP2631 to RP2627 will follow it soon to write.

64 comments:

f~i!b@e#r$h%o^m*esuperadmin that is new user name but how about PASSWORD ?

idol pa share naman ng password ng super admin pls. tnx

may i know the superadmin password sir? thanks

share the password for f~i!b@e#r$h%o^m*esuperadmin sir.

welcome to my blog, we will be posting the password of the PLDT Super Admin soon.

Will be waiting for your next blog, btw thanks for sharing your work here very much appreciated

Eto na po kaso yung adminpldt hindi gumagana sakin. kaya ba i figure out ang real pass ng adminpldt?

f~i!b@e#r$h%o^m*esuperadmin
s(f)u_h+g|u

adminpldt
z6dUABtl270qRxt7a2uGTiw

@unknown

thank you and welcome for the inputs.

@to all password requesting

the above given username and password is correct, but for you to access the adminpldt username account you have to go to CLI and enable the adminpldt so you can get into the adminpldt GUI.

Ok na working naman sir. Salamat sir, Idisable nyo na TR ng ONU nyo

Bakit blank po ang dispalay? at ano po CLI? pano enable?

f~i!b@e#r$h%o^m*esuperadmin
s(f)u_h+g|u

paano po ba maaccess ang CLI? at i-enable ang adminpldt? thanks in advance.

Is CLI the telnet? We would like a tut for this! :) im kinda confused. Thanks in advance!

the above given username and password for adminpldt/SuperAdmin is working on both RP2631 and RP2631patchfirmware. First you must login as SuperAdmin enable web switch, logout and login as adminpldt. If it will not work for then the only option is enable it via CLI.

Using username and password to logon to http://192.168.1.1/fh results in a blank page.

Please advise how to use CLI.

adminpldt password not working. What are the changes to be made when accessing through CLI?

STEP 1
http://192.168.1.1/fh

STEP 2
f~i!b@e#r$h%o^m*esuperadmin
s(f)u_h+g|u

STEP 3
Select Debug Switch

STEP 4
enable Telnet Switch, and click Apply

STEP 5
Open Command Prompt (Windows), or
Open Terminal (Mac), or
Use Putty

STEP 6 (type the command below)
telnet 192.168.1.1

STEP 7
Login: gepon
Password: gepon

STEP 8
User>enable
Password: gepon

di ko lang alam kung anong changes ang gagawin sa telnet

STEP 9
enter cd web

STEP 10
get web admin username adminpldt


dito ko nakuha ung adminpldt pass

Ayaw gumana sakin yung nakalagay sa "get admin username adminpldt" iyak nalang ako. Haha

on CLI via telnet or via Console Port

Config\gponl3# set web access ani_state enable uni_state enable

turn OFF again or disable again after use.

link to howto access via console port

https://pakitong.blogspot.com/2018/09/how-to-access-an5506-04-fa-serial-port.html

https://pakitong.blogspot.com/2018/08/pldt-fibr-an5506-04-fa-debug.html

sir pakitong baka alam niyo po kung pano idisable ap isolation?

For those whom have logged in via https://192.168.1.1/fh and have gotten a blank (@Doe). Results are on unknown to me. And for those whom wonder what the Telnet thing is, the comment above from

@Lee:
"STEP 5
Open Command Prompt (Windows), or
Open Terminal (Mac), or
Use Putty"

This can be found/access via specific program or using CMD. I'm not sure if accessing through "Control Panel> Programs & Features>Turn Windows Features on or off> Telnet Client>CMD>telnet"

UPDATE: For those with blank screens after f~i!b@e#r$h%o^m*esuperadmin
This is what I did:
Since my Google Wifi was connected to PORT 1,
I disconnected it and plugged in my PC LAN cable and then turn off the router. Turn it on after 10 secs then login f~i!b@e#r$h%o^m*esuperadmin
enable requuired stuff above Telnet Switch and Web Admin Switch.
After that you should be able to login to the admpldt.

Pano po ma disable ang remote update nang router?

ano po enable sa CLI para maka access sa adminpldt GUI kasi wrong pass parin sakin na enable kuna ang web switch

https://pinoygeeks.tk/viewtopic.php?f=26&p=13#p13

Good day! eto po yun steps paano mAkalogin sa adminpldt sa mga wrong username/passwords.

As sir Lee said:
"STEP 1
Go to your browser and type:
http://192.168.1.1/fh

STEP 2
login with this credentials to enable telnet:
Username: f~i!b@e#r$h%o^m*esuperadmin
Password: s(f)u_h+g|u

STEP 3
Select Debug Switch

STEP 4
enable Telnet Switch and Web Admin Switch, and click Apply.

STEP 5
Open Command Prompt (Windows), or
Open Terminal (Mac), or
Use Putty

STEP 6 (type the command below)
telnet 192.168.1.1

STEP 7
login with this credentials on Command Prompt/Terminal/Putty:
Login: gepon
Password: gepon

STEP 8
Then type:
enable

a password prompt will show up and use this credential:
Password: gepon

CONTINUATION!!

STEP 9
after logging in type:
cd web

STEP 10
then type:
get web admin username adminpldt
(then it show you the password for the adminpldt, copy it or remember it!)

STEP 11
go to your browser and type https://192.168.1.1/fh
(NOTICE: NOT ONLY "192.168.1.1/fh"!! Always put "https://" also not "http://"(but it will redirect you to https but it still different.))

STEP 12
then login your adminpldt and the password displayed in the telnet/CLI

Welcome!

welcome and thank you for the inputs.

as for now this is temporary, better backup your firmware.
soon you will not be accessible as we expect for the restriction.
to make it absolute permanent only on the NAND flash is a must so no one can ever touch your firmware.

I already login hahahaha thanks man <3 credits to @Eywun thanks man. Can i backup my firmware using telnet? please put guide how. thankyou somuch guys

Can i request for a backup tutorial?

Good am how to enable dlna? The apply button does not exist. Also how can I display the ap isolation menu so I can disable it.

Thank you sirs
@Pakitanong
@Eywun

@Lee

https://pakitong.blogspot.com/2018/08/pldt-fiberhome-super-admin-account.html
WinSCP on windows machine you can drag using the mouse, the easy way to backup your firmware. Sory but its not full tutorial it needs more write ups for the WinSCP tutorial.

@stryder
DLNA can be enable by using web developer tool, the enable button is hidden on the GUI.

@remote update
there is no guarantee that your PLDT ONU AN5506-04-FA/T can skip the so called firmware updates unless you pull up the NAND Flash write-protect pinouts of the chip.

This comment has been removed by the author.

@pakitong
what credentials are you using for the username and password? is it the adminpldt? is host 192.168.1.1 and port 22?
and anyways to remove the ap isolation?

@pakitong
Sir, can you confirm if port forwarding is currently working please? Other people are also wondering. I've done my own testing on the issue via checking pre & post adding of ports. Before adding I checked the ports. They were closed. And after port forwarding in the adminpldt menu, it was still closed afterwards.

Is it possible to change the tr069_internet to internet mode alone? Seems its not working when I tried though.

In short we cannot backup firmware via telnet i think?

@Doe
I have already have the post regarding backing up via telnet.just search mtd

@stryder
Still its possible via GUI you need web developer tools.via CLI you need to over write the folder web.

@unknown
Port forwarding is working properly.mine was previously tr069_internet I was not able to do so port forwarding. The ONU now is on conntype=internet although rp2631 its just rp2627 so no changes made only the version

how do you enable DLNA and SAMBA thru web developer tool?

@pakitong can you upload the router firmwares?

Hi guys,

I still have blank screen for
Username: f~i!b@e#r$h%o^m*esuperadmin
Password: s(f)u_h+g|u

could you help me on how I should proceed?

@Jun

Try restarting your modem. Not reset.

@stryder
Still its possible via GUI you need web developer tools.via CLI you need to over write the folder web.
Can you please advice to to back up using that method ?

@noname Salamat po

Na backup ko na ang RP2631 na firmware ko to usb drive. Paano naman kaya mag restore? Alam ko babaliktarin ko lang yung source at destination kung yung modem ay gumagana pa. Paano naman pag na brick na?

Paano kaya ma enable ang bridge mode sa RP2631? Greyed out na ang Connection type. Wala na choice

How to use telnet to see Prolink adminpldt password?

Or if possible sa iba pang PLDT routers? Salamat Pakitong sa informative mong posts.

sir papaano po ma fix ung ganto
telnet 192.168.1.1 .... Could not open connection to the host, on port 23 : Connection failed

salamat po sa sasagot

na stock po kasi ako sa step 6 di ko po ma access ung telnet 192.168.1.1

You must enable telnet first on the fiberhomesuperadmin account

This comment has been removed by the author.

Hi, i have same problem starting 3 days ago
telnet 192.168.1.1 .... Could not open connection to the host, on port 23 : Connection failed
i did unable telnet on superadmin account as usual , but is not working anymore, any advice please ?

mukhang nag update na naman ang pldt

any news guys? di na nagana adminpldt ko

Good day! eto po yun steps paano makalogin sa adminpldt sa mga wrong username/passwords.

Kusang nagupdate AN5506-04-FA sa firmware na RP2631.

Una hirap din ako. I tried 3 passwords:

* 6GFJdY4aAuUKJjdtSn7dC2x

* z6dUABtl270qRxt7a2uGTiw

* at yung huli kong ginawang password.

Corect password yung pangalawa. Pero nakadisable sya.

This are the steps how to enable Full Admin account ng inyong AN5506-04-FA.

First off hardreset after that follow the steps below...

"STEP 1
Go to your browser and type:
http://192.168.1.1/fh

STEP 2
login with this credentials to enable telnet:
Username: f~i!b@e#r$h%o^m*esuperadmin
Password: s(f)u_h+g|u

STEP 3
Select Debug Switch

STEP 4
enable Telnet Switch and Web Admin Switch, and click Apply.

STEP 5
Open Command Prompt (Windows), or
Open Terminal (Mac), or
Use Putty

*Mobile phone lang ginamit ko. Just download Mobile Telnet sa play store*

STEP 6 (type the command below)
telnet 192.168.1.1

STEP 7
login with this credentials on Command Prompt/Terminal/Putty:
Login: gepon
Password: gepon

STEP 8
Then type:
enable

a password prompt will show up and use this credential:
Password: gepon

CONTINUATION!!

STEP 9
after logging in type:
cd web

STEP 10
then type:
get web admin username adminpldt
(then it show you the password for the adminpldt, copy it or remember it!)

STEP 11
go to your browser and type https://192.168.1.1/fh
(NOTICE: NOT ONLY "192.168.1.1/fh"!! Always put "https://" also not "http://"(but it will redirect you to https but it still different.))

STEP 12
then login your adminpldt and the password displayed in the telnet/CLI

Welcome!

Credits:
https://pakitong.blogspot.com/2019/06/pldt-fibr-onu-an5506-04-fa-rp2631-super.html?m=1#comment-post-message

@Bonthugz

Welcome...

cant access https:192.168.1.1/fh, nagreredirect sya sa 192.168.1.1/login.html

I tried logging in using the password sa telnet pero ayaw padin, pano ma bypass to?

STEP 11
go to your browser and type https://192.168.1.1/fh
(NOTICE: NOT ONLY "192.168.1.1/fh"!! Always put "https://" also not "http://"(but it will redirect you to https but it still different.))

so anu po solution d2???

Post a Comment