MEDIUM · 4.6

CVE-2024-41689

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ database. An attacker with physical access could exploi...

Vulnerability Description

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext WPA/ WPS credentials on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to bypass WPA/ WPS and gain access to the Wi-Fi network of the targeted system.

CVSS Score

4.6

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
SyrotechSy-Gpon-1110-Wdont Firmware3.1.02-231102
SyrotechSy-Gpon-1110-Wdont-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-41689?

CVE-2024-41689 is a vulnerability with a CVSS score of 4.6 (MEDIUM). This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ database. An attacker with physical access could exploi...

How severe is CVE-2024-41689?

CVE-2024-41689 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-41689?

Check the references section above for vendor advisories and patch information. Affected products include: Syrotech Sy-Gpon-1110-Wdont Firmware, Syrotech Sy-Gpon-1110-Wdont.