← Blog · · df00tech

Homer Call Capture Platform Ships with Hardcoded Default Admin Password

breaking ghsa go CVE-2026-62252

What Happened

A GitHub Security Advisory (GHSA-6xp5-7rcx-xfgx, tracked as CVE-2026-62252, CVSS 9.8) discloses that every fresh deployment of the Homer SIP capture platform using internal authentication bootstraps an admin account with a hardcoded default password, sipcapture. According to the advisory, the password hash is embedded directly in config/config.go, and EnsureBootstrapAdminUser() in coordinator/services/auth_bootstrap.go creates the account at startup with no force_change, first_login, or expiry flag set. The advisory also notes the platform's legacy SHA-256 hex hash comparison path keeps this credential functional on any deployment, and a working proof-of-concept is public showing authentication against /api/v3/auth with the default credentials returning a valid admin JWT.

Why It Matters

Homer is used to capture and analyze SIP/VoIP signaling traffic, often deployed at network edges or in telephony infrastructure where it has visibility into call metadata and signaling. Per the advisory, any attacker who can reach the login endpoint of a freshly deployed instance gains immediate, full administrative access — no brute-forcing, rate-limit bypass, or exploit chaining required, since the credential is publicly documented. The exploit status is listed as PoC-public, and the CVSS of 9.8 reflects the low complexity and high impact of unauthenticated-to-admin access. Organizations running internet-facing or insufficiently segmented Homer instances that haven't manually rotated the bootstrap password are directly exposed.

What Defenders Should Do Now

  • Inventory any Homer deployments (github.com/sipcapture/homer-app) and verify whether internal authentication is in use.
  • Immediately rotate the admin password on any instance, and confirm it was changed from the default rather than assumed to be.
  • Check authentication logs for successful logins to the admin account, particularly any using the known default credential, and for subsequent access to user-management or configuration endpoints.
  • Restrict network exposure of the Homer login endpoint (/api/v3/auth) to trusted management networks until a patched version enforcing operator-supplied or randomly generated credentials is available.
  • Watch vendor channels for a fix that removes the hardcoded hash and introduces forced password change on first login, as recommended in the advisory.

This is a fresh disclosure and details may evolve as the project responds and a CVE record is finalized. See the original advisory for full technical details: GHSA-6xp5-7rcx-xfgx.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.