PT-2025-48041 · Syrotech · Sy-Gpon-1110-Wdont

Yashodhanvivek

·

Published

2025-11-25

·

Updated

2025-11-30

·

CVE-2025-63729

CVSS v3.1

9.0

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Syrotech SY-GPON-1110-WDONT SYRO 3.7L 3.1.02-240517
Description An issue exists in Syrotech SY-GPON-1110-WDONT firmware where an attacker can extract the SSL Private Key, CA Certificate, SSL Certificate, and Client Certificates in .pem format from the etc folder.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Insertion into Log File

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-63729

Affected Products

Sy-Gpon-1110-Wdont