MEDIUM🇵🇱 Wersja polska

CVE-2024-41685

CVSS 6.9v4.0pub. 2024-07-26upd. 2024-11-21

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web management interface. An attacker with remote access could exploit this by intercepting transmission within an HTTP session on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to capture cookies and obtain sensitive information on the targeted system.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Syrotech Sy Gpon 1110 Wdont

    HW
    Syrotech
    all versions
  • Syrotech Sy Gpon 1110 Wdont Firmware

    OS
    Syrotech
    3.1.02-231102
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-63729CRITICAL9.0PL ✓same product

Syrotech SY-GPON-1110-WDONT: ujawnienie kluczy SSL w firmware

CVE-2024-41691HIGH7.0same product

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext...

CVE-2024-41687HIGH8.6same product

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text....

CVE-2024-41688HIGH7.0same product

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames...

CVE-2024-41686HIGH7.3same product

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to improper implementation of password pol...