Lucene search

K

Sy-Gpon-1110-Wdont Firmware Security Vulnerabilities

cve
cve

CVE-2024-41684

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing secure flag for the session cookies associated with the router's web management interface. An attacker with remote access could exploit this by intercepting transmission within an HTTP session on the vulnerable system. S...

5.3CVSS

6.6AI Score

0.0005EPSS

2024-07-26 12:15 PM
28
cve
cve

CVE-2024-41685

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web management interface. An attacker with remote access could exploit this by intercepting transmission within an HTTP session on the vulnerable system....

7.5CVSS

6.2AI Score

0.001EPSS

2024-07-26 12:15 PM
33
cve
cve

CVE-2024-41686

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to improper implementation of password policies. A local attacker could exploit this by creating password that do not adhere to the defined security standards/policy on the vulnerable system. Successful exploitation of this vulnera...

3.3CVSS

6.5AI Score

0.0004EPSS

2024-07-26 12:15 PM
29
cve
cve

CVE-2024-41687

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote attacker could exploit this vulnerability by intercepting transmission within an HTTP session on the vulnerable system. Successful exploitation of this vulnerability could allow t...

7.5CVSS

6.9AI Score

0.001EPSS

2024-07-26 12:15 PM
27
cve
cve

CVE-2024-41688

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passwords within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plai...

4.6CVSS

6.8AI Score

0.001EPSS

2024-07-26 12:15 PM
27
cve
cve

CVE-2024-41689

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext WPA/...

4.6CVSS

6.8AI Score

0.001EPSS

2024-07-26 12:15 PM
36
cve
cve

CVE-2024-41690

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of default username and password credentials in plaintext within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to acc...

4.6CVSS

6.7AI Score

0.001EPSS

2024-07-26 12:15 PM
30
cve
cve

CVE-2024-41691

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext within the SquashFS-root filesystem associated with the router's firmware. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary da...

4.6CVSS

6.5AI Score

0.001EPSS

2024-07-26 12:15 PM
31