CVE-2024-41689
July 26, 2024, 12:38 p.m.
Tags
Product(s) Impacted
SyroTech SY-GPON-1110-WDONT Router
Description
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext WPA/ WPS credentials on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to bypass WPA/ WPS and gain access to the Wi-Fi network of the targeted system.
Weaknesses
CWE-798
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
CWE ID: 798Date
Published: July 26, 2024, 12:15 p.m.
Last Modified: July 26, 2024, 12:38 p.m.
Status : Undergoing Analysis
CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
More infoSource
vdisclose@cert-in.org.in