# CVE-2024-41692

## Summary

- **CVE ID:** CVE-2024-41692
- **Severity:** HIGH
- **CVSS Score:** 8.6 (CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- **CWE:** CWE-1191
- **Published:** Jul 26, 2024
- **Last Modified:** Mar 13, 2026

## Description

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the root shell on the vulnerable system.

Successful exploitation of this vulnerability could allow the attacker to execute arbitrary commands with root privileges on the targeted system.

## Affected Products

- SyroTech — SyroTech SY-GPON-1110-WDONT router (3.1.02-231102)

## References

- [CNA](https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225)
- [CVE](https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.27%
- **EPSS Percentile:** 19.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._