PT-2025-39363 · Syrotech · Sy-Gpon-2010-Wadont Router

Published

2025-09-25

·

Updated

2025-09-25

·

CVE-2025-10957

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Syrotech SY-GPON-2010-WADONT router (affected versions not specified)
Description The Syrotech SY-GPON-2010-WADONT router contains a flaw related to improper access control within its FTP service. A remote attacker can connect via FTP using default credentials and potentially gain unauthorized access to sensitive information, including configuration files and user credentials, stored on the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-10957

Affected Products

Sy-Gpon-2010-Wadont Router