CVE-2024-41692
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the root shell on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary commands with root privileges on the targeted system.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 0.27%
- CWE
- CWE-1191
- Published
- 2024-07-26
- Last modified
- 2026-03-13
Affected products
- SyroTech SyroTech SY-GPON-1110-WDONT router
Weakness type
Related vulnerabilities
- CVE-2026-15203 — Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 Marine and iC7 7Hybrid software
- CVE-2026-8989 — Open Recovery Mode
- CVE-2026-8988 — Access to Bootloader
- CVE-2024-36319 — Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to...
- CVE-2025-52533 — Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a...
- CVE-2025-15083 — TOZED ZLT M30s UART on-chip debug and test interface with improper access control
- CVE-2025-36755 — CleverDisplay BlueOne unauthorized BIOS access through physical USB keyboard
- CVE-2025-12114 — Serial Console Enabled