← Vulnerability feed

Vulnerability record · CVE-2024-41687 · published 26 July 2024

CVE-2024-41687: Syrotech sy-gpon-1110-wdont firmware cleartext transmission vulnerability

Syrotech · Sy Gpon 1110 Wdont Firmware

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote attacker could exploit this vulnerability by intercepting transmission within an HTTP session on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the targeted system.

8.6 CVSS 4.0 High EPSS 0.31% · top 78.5% CWE-319 · Cleartext transmission
8.6CVSS 4.0 base score
0.31%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote attacker could exploit this vulnerability by intercepting transmission within an HTTP session on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the targeted system.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-41687 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.0CVE-2025-63729Syrotech sy-gpon-1110-wdont firmware information exposure vulnerabilityAn issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SS…EPSS 0.09%7.3CVE-2024-41686Syrotech sy-gpon-1110-wdont firmware vulnerabilityThis vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to improper implementation of password policies. A local attacker could exploit t…EPSS 0.16%7.0CVE-2024-41688Syrotech sy-gpon-1110-wdont firmware cleartext storage of sensitive data vulnerabilityThis vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passwords within the router's firm…EPSS 0.11%7.0CVE-2024-41690Syrotech sy-gpon-1110-wdont firmware cleartext storage of sensitive data vulnerabilityThis vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of default username and password credentials in plaintext within the r…EPSS 0.15%7.0CVE-2024-41691Syrotech sy-gpon-1110-wdont firmware cleartext storage of sensitive data vulnerabilityThis vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext within the SquashFS-root filesystem as…EPSS 0.15%6.9CVE-2024-41684Syrotech sy-gpon-1110-wdont firmware vulnerabilityThis vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing secure flag for the session cookies associated with the router's web m…EPSS 0.21%6.9CVE-2024-41685Syrotech sy-gpon-1110-wdont firmware incorrect permission assignment vulnerabilityThis vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web…EPSS 0.50%5.2CVE-2024-41689Syrotech sy-gpon-1110-wdont firmware hard-coded credentials vulnerabilityThis vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ data…EPSS 0.15%

Source: NIST National Vulnerability Database (record CVE-2024-41687), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.