← back
CVE-2024-41692highCWE-1191

Incorrect Access Control Vulnerability

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.6epss 0.3%
exploitation probability
0.3%top 81% of all CVEs
observed exploitation
nono source reports it
In short

A SyroTech router has an unprotected root terminal accessible via a physical serial port, allowing anyone with physical access to run commands as the administrator. This is a serious risk for anyone using this router at home or in a business.

Technical detail

CWE-1191 describes improper access control on initialization, maintenance, debug, or test interfaces. The SY-GPON-1110-WDONT exposes an unauthenticated root shell on its serial interface, enabling local privilege escalation via physical access without authentication. Successful exploitation grants arbitrary command execution with root privileges.

Summary generated and translated by AI from the official description.
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the root shell on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary commands with root privileges on the targeted system.
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H