CVE-2024-41691
Syrotech
CVE-2024-41691: Plaintext FTP credentials found in SyroTech router firmware. This vulnerability allows an attacker with physical access to the SY-GPON-1110-WDONT router to extract the firmware, reverse engineer it, and obtain the plaintext FTP credentials. Although the CVSS score is 4.6, indicating medium severity, the SOCRadar Vulnerability Risk Score (SVRS) is 47. This highlights the potential for exploitation, especially given the "In The Wild" tag. Successful exploitation grants unauthorized FTP server access. While not immediately critical (SVRS < 80), the ease of access to credentials makes it a significant security risk. Prompt firmware updates or router replacement are recommended to mitigate this vulnerability.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.