CVE-2024-41686
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to improper implementation of password policies. A local attacker could exploit this by creating password that do not adhere to the defined security standards/policy on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to expose the router to potential security threats.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.3
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.16%
- CWE
- CWE-179
- Published
- 2024-07-26
- Last modified
- 2026-03-13
Affected products
- SyroTech SyroTech SY-GPON-1110-WDONT router
Weakness type
Related vulnerabilities
- CVE-2026-49414 — ASLR bypass for setuid executables via procctl(2)
- CVE-2026-3832 — Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response
- CVE-2025-4759 — Versions of the package lockfile-lint-api before 5.9.2 are vulnerable to Incorrect Behavior Order:...
- CVE-2022-1271 — An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied...