CVE 8.7 HIGH

Unrestricted FTP Access Vulnerability in Syrotech Router_CVE-2025-10957

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

This vulnerability exists in the Syrotech SY-GPON-2010-WADONT router due to improper access control in its FTP service. A remote attacker could exploit this vulnerability by establishing an FTP connection using default credentials, potentially gaining unauthorized access to configuration files, user credentials, or other sensitive information stored on the targeted device.

Basic Information

ID CVE-2025-10957
Source CERT-In
Published Sep 25, 2025 at 11:43

Affected Product

Vendor Syrotech Networks
Product Syrotech SY-GPON-2010-WADONT
Version V2.1.05-210329
Affected Versions Syrotech Networks Syrotech SY-GPON-2010-WADONT V2.1.05-210329

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.