CVE-2024-41692

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the root shell on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary commands with root privileges on the targeted system.
CVSS

No CVSS.

Configurations

No configuration.

History

01 Aug 2024, 08:15

Type Values Removed Values Added
References
  • {'url': 'https://cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225', 'source': 'vdisclose@cert-in.org.in'}
  • () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0225 -

29 Jul 2024, 14:12

Type Values Removed Values Added
Summary
  • (es) Esta vulnerabilidad existe en el enrutador SyroTech SY-GPON-1110-WDONT debido a la presencia de acceso a terminal root en una interfaz serial sin el control de acceso adecuado. Un atacante con acceso físico podría aprovechar esto accediendo al shell root en el sistema vulnerable. La explotación exitosa de esta vulnerabilidad podría permitir al atacante ejecutar comandos arbitrarios con privilegios de root en el sistema objetivo.

26 Jul 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-26 13:15

Updated : 2024-08-01 08:15


NVD link : CVE-2024-41692

Mitre link : CVE-2024-41692

CVE.ORG link : CVE-2024-41692


JSON object : View

Products Affected

No product.

CWE
CWE-1191

On-Chip Debug and Test Interface With Improper Access Control