CVE-2025-63729
CRITICALSyrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 - Info Disclosure
Title source: llmDescription
An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SSL Certificate, and Client Certificates in .pem format in firmware in etc folder.
Exploits (1)
nomisec
STUB
by Yashodhanvivek · poc
https://github.com/Yashodhanvivek/CVE-2025-63729-Syrotech-SY-GPON-1110-
Scores
CVSS v3
9.0
EPSS
0.0001
EPSS Percentile
0.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Details
CWE
CWE-532
CWE-200
CWE-312
Status
published
Products (1)
syrotech/sy-gpon-1110-wdont_firmware
3.1.02-240517
Published
Nov 25, 2025
Tracked Since
Feb 18, 2026