← Vulnerability feed

Vulnerability record · CVE-2025-63729 · published 25 November 2025

CVE-2025-63729: Syrotech sy-gpon-1110-wdont firmware information exposure vulnerability

Syrotech · Sy Gpon 1110 Wdont Firmware

An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SSL Certificate, and Client Certificates in .pem format in firmware in etc folder.

9.0 CVSS 3.1 Critical EPSS 0.09% · top 99.7% CWE-200 · Information exposureCWE-312 · Cleartext storage of sensitive data
9.0CVSS 3.1 base score
0.09%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SSL Certificate, and Client Certificates in .pem format in firmware in etc folder.

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-63729 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2024-41687Syrotech sy-gpon-1110-wdont firmware cleartext transmission vulnerabilityThis vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote attacker could exploit this v…EPSS 0.31%7.3CVE-2024-41686Syrotech sy-gpon-1110-wdont firmware vulnerabilityThis vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to improper implementation of password policies. A local attacker could exploit t…EPSS 0.16%7.0CVE-2024-41688Syrotech sy-gpon-1110-wdont firmware cleartext storage of sensitive data vulnerabilityThis vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passwords within the router's firm…EPSS 0.11%7.0CVE-2024-41690Syrotech sy-gpon-1110-wdont firmware cleartext storage of sensitive data vulnerabilityThis vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of default username and password credentials in plaintext within the r…EPSS 0.15%7.0CVE-2024-41691Syrotech sy-gpon-1110-wdont firmware cleartext storage of sensitive data vulnerabilityThis vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext within the SquashFS-root filesystem as…EPSS 0.15%6.9CVE-2024-41684Syrotech sy-gpon-1110-wdont firmware vulnerabilityThis vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing secure flag for the session cookies associated with the router's web m…EPSS 0.21%6.9CVE-2024-41685Syrotech sy-gpon-1110-wdont firmware incorrect permission assignment vulnerabilityThis vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web…EPSS 0.50%5.2CVE-2024-41689Syrotech sy-gpon-1110-wdont firmware hard-coded credentials vulnerabilityThis vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ data…EPSS 0.15%

Source: NIST National Vulnerability Database (record CVE-2025-63729), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.