Skip to content

Instantly share code, notes, and snippets.

@kleo
Last active July 7, 2024 16:31
Show Gist options
  • Save kleo/de3b1610b1879f8e92966ba106f83f97 to your computer and use it in GitHub Desktop.
Save kleo/de3b1610b1879f8e92966ba106f83f97 to your computer and use it in GitHub Desktop.
backspace

Project moved due to excessive amount of unicorns. Repo https://git.io/adminpldt

Our community of amazing people. Managed by a cat. Backspace https://discord.gg/C43625u

Gist here will not be updated anymore Discussion here on Gist is still allowed but I strongly recommend going over to the repository or Discord chat


PLDT HOME FIBR AN5506-04-FA RP2627 Advanced Settings

By default the PLDT HOME FIBR AN5506-04-FA RP2627 comes only with limited settings.

The following walkthrough consists of opening the device and enabling the advanced settings using the device serial console to enable access to the admin account on the web interface.

Rules

Avoid directly posting images, it causes this page to become heavier and load much longer. Use links to image hosting sites https://i.imgur.com/UqX95Pb.gifv

Avoid 3rd party link shorteners

A lot of answers have already been answered, backread before asking.

This is not your ISP support thread. Effort and time devoted by people on this thread is not paid for. Do not ask to be spoon-fed.

Disclaimer

This will void your device ISP warranty. Any modification done to your device comes with no guarantee.

Help from other members are appreciated, follow under your own discretion. We have no responsibility to any damage that can happen to any of your devices. Mod at your own risk.

Walkthrough

A walkthrough on hacking the PLDT FIBR AN5506-04-FA RP2627 router

PLDT Home Fiber router hacking
PLDT Home Fiber router console access
PLDT Home Fiber router firmware and files
PLDT Home Fiber router web interface admin access

Frequently Asked Questions

How to activate LAN PORTS 2-4 / Remove AP ISOLATION?

  1. Gain admin access

Instructions: https://kbeflo.github.io/2018/09/09/PLDT-Home-Fiber-web-interface-admin-access/

  1. On the web interface, Network > BroadBand Settings > Internet Settings

Check all the boxes on: LAN Binding, 2.4G SSID Binding and 5G SSID Binding

Example: https://kbeflo.github.io/img/2018-09-09/01.png

Hidden URLs

The URLs were usable from version RP2616 and lower but as of RP2627 update the URLs below are now restricted and will redirect back to the login page.

Hidden from the web interface are the rest of the router's capabilities and advanced settings.

We just need to enter the right url for the settings you're looking for.

We need to be logged in before we can do anything else, use your defined password if you already set the admin password.

Note that you have to log in again if you're idle for a few minutes on the web interface.

username: admin
password: 1234
http://192.168.1.1/application/ddns.asp			# Configure DDNS
http://192.168.1.1/application/dlna.asp                 # Enable or disable DLNA service
http://192.168.1.1/application/dmz.asp			# Set host IP to DMZ
http://192.168.1.1/application/multi_nat.asp            # Configure Multi NAT
http://192.168.1.1/application/samba.asp                # Enable or disable samba service
http://192.168.1.1/application/ping_diagnosis.asp	# Network diagnosis. Ping and Traceroute
http://192.168.1.1/application/port_forwarding.asp      # Configure port forwarding
http://192.168.1.1/application/port_trigger.asp         # Configure port trigger
http://192.168.1.1/application/redirect.asp		# blank
http://192.168.1.1/application/upnp.asp			# Configure UPnP enable/disable

http://192.168.1.1/help/

http://192.168.1.1/internet/dhcp_macband.asp            # blank
http://192.168.1.1/internet/dhcp_portband.asp           # blank
http://192.168.1.1/internet/dhcp_service.asp		# Enable/disable DHCP functions, configure parameters
http://192.168.1.1/internet/dhcpv6_portband.asp         # blank
http://192.168.1.1/internet/dhcp_userlist.asp		# Display information about DHCP client, include IP address, MAC address and lease
http://192.168.1.1/internet/ipv6_static_route.asp       # Configure IPv6 static route
http://192.168.1.1/internet/lan.asp			# Setup router IP address and subnet mask
http://192.168.1.1/internet/pppoe_accout.asp            # Modify PPPoE account
http://192.168.1.1/internet/qos.asp                     # blank
http://192.168.1.1/internet/wan_romania.asp             # Choose different connection type suitable for your environment. Besides, you may also configure parameters according to the selected connection type (!)
http://192.168.1.1/internet/wan_sfu.asp                 # Choose different connection type suitable for your environment. Besides, you may also configure parameters according to the selected connection type (!)
http://192.168.1.1/internet/wan_user.asp		# blank

http://192.168.1.1/log/log.asp			        # View router logs

http://192.168.1.1/management/account_admin.asp         # Configure admin account
http://192.168.1.1/management/account_self_admin.asp	# Configure admin account
http://192.168.1.1/management/account_self_admin_toacs.asp
http://192.168.1.1/management/down_cfgfile.asp          # Backup several config files from device to PC as you wish after opening the ftp tool
http://192.168.1.1/management/ftp_server.asp            # Configure FTP server
http://192.168.1.1/management/ntpchecktime.asp          # Configure time
http://192.168.1.1/management/reboot.asp	        # Reboot
http://192.168.1.1/management/restore.asp       	# Restore device configuration (!)
http://192.168.1.1/management/update.asp	        # Upgrade firmware (!)

http://192.168.1.1/menu/

http://192.168.1.1/ont_auth/sncfg.asp                   # Modify the ONU authentication-related parameters to authenticate the OLT

http://192.168.1.1/security/acl.asp                     # Configure ACL enable/disable, and enabled rules
http://192.168.1.1/security/ddos.asp		        # Enable/disable DDOS
http://192.168.1.1/security/dhcp_filter.asp             # Blocking the MAC address to get the DHCP
http://192.168.1.1/security/firewall_enable.asp		# Configure firewall enable/disable
http://192.168.1.1/security/https_enable.asp		# Enable/disable Https
http://192.168.1.1/security/ip_filter.asp		# Filter ipv4 if firewall is enabled
http://192.168.1.1/security/ipv6_filter.asp		# Filter ipv6 if firewall is enabled
http://192.168.1.1/security/macaddr_filter.asp		# Filter mac addresses if firewall is enabled
http://192.168.1.1/security/macaddr_v6_filter.asp       # Filter mac addresses if firewall is enabled
http://192.168.1.1/security/parental_control.asp	# Parental Control
http://192.168.1.1/security/port_scan.asp		# Configure Anti Port Scan enable/disable
http://192.168.1.1/security/qos_enable.asp              # Enable/disable Route QOS
http://192.168.1.1/security/remote_control.asp		# Access the web interface through WAN (!)
http://192.168.1.1/security/route_qos.asp               # Configure Route QOS
http://192.168.1.1/security/url_filter.asp		# Filter urls if firewall is enabled
http://192.168.1.1/security/wan_acl.asp                 # Configure network access control based on internet WAN port
http://192.168.1.1/security/wps.asp                     # Configure WPS

http://192.168.1.1/state/deviceInfor.asp		# Device information
http://192.168.1.1/state/lan_state.asp			# LAN state
http://192.168.1.1/state/lan_state_count.asp            # Query the state of LAN port
http://192.168.1.1/state/opt_power.asp			# Optical power state
http://192.168.1.1/state/pon_info.asp                   # Query information of PON interface
http://192.168.1.1/state/voip_auth_status.asp		# VoIP state
http://192.168.1.1/state/wan_state.asp			# WAN interface state
http://192.168.1.1/state/wan_state_user.asp             # WAN interface state
http://192.168.1.1/state/wireless_state.asp		# Wireless state
http://192.168.1.1/state/wireless_state_5g.asp		# Wireless 5GHz state

http://192.168.1.1/tr069/tr069.asp                      # Configure the url, username, password, connectionRequestUsername, connectionRequestPassword of TR069 basic settings (!)

http://192.168.1.1/voip/

http://192.168.1.1/wireless/basic.asp			# Configure wireless settings
http://192.168.1.1/wireless/basic_5g.asp		# Configure wireless 5GHz settings
http://192.168.1.1/wireless/security_romania.asp	# Configure wireless password and encryption
http://192.168.1.1/wireless/security.asp		# Configure wireless password and encryption
http://192.168.1.1/wireless/security_5g.asp		# Configure wireless 5GHz password and encryption
http://192.168.1.1/wireless/wifimaclist.asp		# WIFI clients list
http://192.168.1.1/wireless/wifipowerctrl.asp		# Set WIFI power and the number of WIFI access here
http://192.168.1.1/wireless/wifipowerctrl_5g.asp        # Set WIFI power and the number of WIFI access here

# Resource files

http://192.168.1.1/js/utils.js
http://192.168.1.1/js/checkValue.js
http://192.168.1.1/js/versionControl.js
http://192.168.1.1/js/jquery.js
http://192.168.1.1/js/menu_tips.js
http://192.168.1.1/js/frame_romania.js
http://192.168.1.1/js/menuparse.js
http://192.168.1.1/js/ajaxupload.3.2.js
http://192.168.1.1/js/frame_3bb.js
http://192.168.1.1/js/wan.js
http://192.168.1.1/js/wifibasic.js

http://192.168.1.1/lang/b28n.js
http://192.168.1.1/lang/en/account.xml
http://192.168.1.1/lang/en/firewall.xml
http://192.168.1.1/lang/en/internet.xml
http://192.168.1.1/lang/en/log.xml
http://192.168.1.1/lang/en/menu.xml
http://192.168.1.1/lang/en/restore.xml
http://192.168.1.1/lang/en/state.xml
http://192.168.1.1/lang/en/wireless.xml
http://192.168.1.1/lang/en/errorpage.xml

http://192.168.1.1/menu/sfu/ph_pldt/hisi5116/voip_dualwifi/sip/1.xml
http://192.168.1.1/menu/hgu/ecuador/voipwifi/sip/1.xml
http://192.168.1.1/menu/hgu/romania/voipwifi/sip/1.xml

http://192.168.1.1/style/frame_pldt.css
http://192.168.1.1/style/style.css
http://192.168.1.1/style/frame_romania.css
@jeolives
Copy link

jeolives commented Nov 23, 2019

Globally routable IPv6 addresses have been available since September. [1] [2] [3] [4] [5]
They hand out /56 prefixes, as per the IETF recommendations. I get lower latency with IPv6 than IPv4.
My devices get two IPv6 addresses via SLAAC (one real, one adhering to SLAAC privacy extensions).
If it ever comes to, just disable IPv4 when you get CG-NAT'd.

[1] https://www.reddit.com/r/ipv6/comments/dbbwfb/our_isp_here_in_the_philippines_pldt_just/
[2] https://www.reddit.com/r/Philippines/comments/crkttt/pldt_ipv6_being_rolled_out_in_the_philippines/
[3] image
[4] Screen Shot 2019-11-23 at 14 30 48
[5] image

@pakitong
Copy link

Another updates by Unknown its RP2684 this is infinity, Fiberhome OLT/ONU is a big headache for PLDT that is why the Giant Telco shifting to HUAWEI OLT/ONU as their new FTTH.
@ jeolives
PLDT is just complying for IPv6 as an ISP in the country but not implementing the IPv6 to their whole FARM.

@kewubenduben
pie0 is not pihole, its PON interface Ethernet for AN5506-04-FA/T and not for AN5506-04-F

Good you can just UN-CGNAT permanently, I haven't tried yet injecting my old FW to my ONU.

you can chat me via FB
https://www.facebook.com/pakitong33

@jeolives
Copy link

@jeolives
PLDT is just complying for IPv6 as an ISP in the country but not implementing the IPv6 to their whole FARM.

One of the people who work for them said it's in alpha/beta rollout, someone else [1] also had received the same answer. They flip the switch on your ONU. It's probably the reason as to why there has been a rapid succession of updates, and everyone is getting RP2631/40/84.

This is also probably why they still have a 2001: IPv6 prefix. Proper Asia-Pacific IPv6 addresses should all start with 240(X):[2]. So I agree that they are just in compliance testing rather than full rollout right now.

[1]
Screen Shot 2019-11-25 at 21 30 33

[2]
image

@kewubenduben
Copy link

@kewubenduben
pie0 is not pihole, its PON interface Ethernet for AN5506-04-FA/T and not for AN5506-04-F

Good you can just UN-CGNAT permanently, I haven't tried yet injecting my old FW to my ONU.

you can chat me via FB
https://www.facebook.com/pakitong33

thanks for info about the pie0 intf.

I don't have FB, do you frequent on Discord? I posted some stuff there.

Anyway, let's chat soon

@kewubenduben
Copy link

Also, I've tried running full IPv6 on my LAN. It works well. Thanks for the post about its possibilities

@capthndsme
Copy link

Anyone on black modem here? sfuhgu and the special character variant no longer works.. and also somehow my IPv6 got disabled.

@Burgercat
Copy link

^^ PLDT changed the fiberhomesuperadmin creds again. I don't know why IPv6 got disabled though.

@pakitong
Copy link

IPv6 works but its useless for DDNS so far no solution for Public IP yet, Fiberhome ONU is a big headache for PLDT no wonder they will keep on patching and patching until all subs will shift to the new Telco.

@Burgercat
Copy link

@pakitong where can i message you privately except for facebook?

@pakitong
Copy link

pakitong commented Dec 2, 2019

@ DerpyGamah

I can be available at Discord #4661

@kismet-07
Copy link

ayaw po gumana nong f~i!b@e#r$h%o^m*esuperadmin at s(f)u_h+g|u as username and password. I tried it yesterday lang kasi biglang nag update yong router ko. I can't no longer access the super admin. My modem version is RP2684 and the model is AN5506-04-F. please help me I really need it so bad because I cannot access my project anymore online.

@Burgercat
Copy link

^^ Well we can't do anything about that until someone releases the new credentials

@kismet-07
Copy link

I really hope that someone can give me the new username and password for full access because I can't run my project and I really need it so bad.

@pakitong
Copy link

pakitong commented Dec 5, 2019

IPv6 is also now disabled.. WTF...

@kismet-07
my old ONU already replaced with new AN5506-04-FA verRP2627 by PLDT for FREE without any additional cost to pay, I just said it that its not accessible and the organic Team are lazy to do the troubleshooting.

@pakitong
Copy link

Finally welcome back to my Dynamic Public IP addresses, say goodbye to PLDT Home Fibr CGNAT again.

@marxman8
Copy link

marxman8 commented Jan 4, 2020

Hi,

do you have any workarounds for disabling ethernet isolation withour serial on pldt hg6245d modem?

thanks
marxman

@Burgercat
Copy link

Please join the Discord server at this link https://discord.gg/C43625u to get better support for your problems. Most of the people already ask for help there.

@dustin1220
Copy link

dustin1220 commented Jan 20, 2020

Does anyone know how to configure my white UNO from black? I want to change my old router with this new white one which i aquire from onther fiber subscriber. Thanks i hope somebody can help.

@jolo22
Copy link

jolo22 commented Jan 24, 2020

Looks Like IPv6 is enabled again (sort of)

@tampy9
Copy link

tampy9 commented Feb 1, 2020

Sir pano pag mali yung GEPON pw? Ayaw niya gumana

@bongsky2-0
Copy link

@pakitong paps .. pano ba malalaman kung under k ng CGNAT???

@johnnixjaz
Copy link

iba na naman ba ang password ng admin ng router?

Software Version | RP2646
Hardware Version | WKE2.134.285F1A
Device Model | AN5506-04-FA
Device Description | GPON
ONU State | O5(STATE_OPERATION)
ONU Regist State | OK
LOID |  
CPU Usage | 8.19%
Memory Usage | 44.52%
Web Server port | 443

Di na naman ako makapasok sa full admin eh. Di na ata gumagana yung f~i!b@e#r$h%o^m*esuperadmin
s(f)u_h+g|u na user at password

@Burgercat
Copy link

Burgercat commented Feb 14, 2020

please join the discord server at https://discord.gg/6r6u4jj for answers. this gist is no longer active and will no longer be updated.

@Xavier300
Copy link

@johnnixjaz oo iba naa ser

@Xavier300
Copy link

@johnnixjaz oo iba naa ser

@jivexyz
Copy link

jivexyz commented Sep 15, 2020

try this, worked for me: https://youtu.be/MK9WCWqoQMI
PLDT HOME FIBR SEPT 2020 RESET MODEM/ROUTER, FORGOT PASSWORD, SUPERADMIN ACCESS RP2646

@msenetra
Copy link

I have an unused an5506-04-FG modem, has anyone managed to use it only as a wifi router? how to configure?

@Burgercat
Copy link

please join the discord server at https://discord.gg/6r6u4jj for answers. this gist is no longer active and will no longer be updated.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment