cert-in.org.inThird-party advisory
https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225 CVE-2024-41692
HIGH
Incorrect Access Control Vulnerability
Record summary
CVE-2024-41692 has a selected CVSS score of 8.6 (high).
Description
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the root shell on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary commands with root privileges on the targeted system.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 26, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
SyroTech SY-GPON-1110-WDONT routerBrowse SyroTech / SyroTech SY-GPON-1110-WDONT routerDefault status: unaffected | CVE List | 3.1.02-231102 | affected |
sy-gpon-1110-wdont_firmwareBrowse syrotech / sy-gpon-1110-wdont_firmwareDefault status: unknown | CVE List | 3.1.02-231102 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-41692 cert-in.org.inThird-party advisory
https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225