8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
This vulnerability exists in the Syrotech SY-GPON-2010-WADONT router due to improper access control in its FTP service. A remote attacker could exploit this vulnerability by establishing an FTP connection using default credentials, potentially gaining unauthorized access to configuration files, user credentials, or other sensitive information stored on the targeted device.
Basic Information
ID
CVE-2025-10957
Source
CERT-In
Published
Sep 25, 2025 at 11:43
Affected Product
Vendor
Syrotech Networks
Product
Syrotech SY-GPON-2010-WADONT
Version
V2.1.05-210329
Affected Versions
Syrotech Networks Syrotech SY-GPON-2010-WADONT V2.1.05-210329