Syrotech's vulnerability profile centers on a narrowly scoped fiber-optic access device, the SY-GPON-1110, deployed in broadband and carrier networks where credential exposure and improper access controls present significant risk. The observed weakness classes—cleartext storage and transmission of credentials, exposure of sensitive information, and incorrect permission assignments—cluster around authentication and data-protection mechanisms endemic to network-access equipment, and the vendor's disclosures skew toward serious outcomes. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Syrotech over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-63729CRITICAL An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SSL Certificate, and Client Certi | Nov 25, 2025 | 9.0 | 32 | NO | NO |
CVE-2024-41687HIGH This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote attacker could exploit this vulnerability by intercepting tr | Jul 26, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-41685HIGH This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web management interface. An attac | Jul 26, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-41688MEDIUM This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passwords within the router's firmware/ database. An attacker wit | Jul 26, 2024 | 4.6 | 18 | NO | NO |
CVE-2024-41684MEDIUM This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing secure flag for the session cookies associated with the router's web management interface. An attacke | Jul 26, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-41691MEDIUM This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext within the SquashFS-root filesystem associated with the router's firm | Jul 26, 2024 | 4.6 | 16 | NO | NO |
CVE-2024-41690MEDIUM This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of default username and password credentials in plaintext within the router's firmware/ database. An | Jul 26, 2024 | 4.6 | 16 | NO | NO |
CVE-2024-41689MEDIUM This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ database. An attacker with physical | Jul 26, 2024 | 4.6 | 16 | NO | NO |
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to improper implementation of password policies. A local attacker could exploit this by creating password that d | Jul 26, 2024 | 3.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Syrotech.
Media articles that mention a CVE ID that affects a product developed by Syrotech — matched by CVE ID, not by vendor name.