CVE-2024-41689 Vulnerability Details

  /     /     /  

CVE-2024-41689 Metadata Quick Info

CVE Published: 26/07/2024 | CVE Updated: 02/08/2024 | CVE Year: 2024
Source: CERT-In | Vendor: SyroTech | Product: SyroTech SY-GPON-1110-WDONT router
Status : PUBLISHED

CVE-2024-41689 Description

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router\'s firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext WPA/ WPS credentials on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to bypass WPA/ WPS and gain access to the Wi-Fi network of the targeted system.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-798
CWE Name: CWE-798: Use of Hard-coded Credentials
Source: SyroTech

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-191
CAPEC Description: CAPEC-191: Read Sensitive Constants Within an Executable


Source: NVD (National Vulnerability Database).