This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passwords within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext credentials on the vulnerable system.

Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the targeted system.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-39133 This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passwords within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext credentials on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the targeted system.
Fixes

Solution

Upgrade SyroTech SY-GPON-1110-WDONT Router firmware to patched version 3.1.02-240517 http://drive.google.com/file/d/1JQc3AkJm69mV0kg2c-b-zzaojc87Rru9/view


Workaround

No workaround given by the vendor.

History

Fri, 22 Nov 2024 12:00:00 +0000


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published:

Updated: 2024-08-02T04:46:52.664Z

Reserved: 2024-07-19T11:24:20.420Z

Link: CVE-2024-41688

cve-icon Vulnrichment

Updated: 2024-07-26T15:19:21.453Z

cve-icon NVD

Status : Modified

Published: 2024-07-26T12:15:03.370

Modified: 2024-11-21T09:32:58.603

Link: CVE-2024-41688

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.