CVE-2025-63729

An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SSL Certificate, and Client Certificates in .pem format in firmware in etc folder.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:syrotech:sy-gpon-1110-wdont_firmware:3.1.02-240517:*:*:*:*:*:*:*
cpe:2.3:h:syrotech:sy-gpon-1110-wdont:3.7l:*:*:*:*:*:*:*

History

30 Dec 2025, 17:17

Type Values Removed Values Added
References () https://github.com/Yashodhanvivek/CVE-2025-63729-Syrotech-SY-GPON-1110-/blob/main/Syrotech_SY-GPON-1110-WDONT_Security_Assessment.pdf - () https://github.com/Yashodhanvivek/CVE-2025-63729-Syrotech-SY-GPON-1110-/blob/main/Syrotech_SY-GPON-1110-WDONT_Security_Assessment.pdf - Exploit, Third Party Advisory
CPE cpe:2.3:h:syrotech:sy-gpon-1110-wdont:3.7l:*:*:*:*:*:*:*
cpe:2.3:o:syrotech:sy-gpon-1110-wdont_firmware:3.1.02-240517:*:*:*:*:*:*:*
First Time Syrotech sy-gpon-1110-wdont Firmware
Syrotech
Syrotech sy-gpon-1110-wdont

25 Nov 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-25 17:15

Updated : 2025-12-30 17:17


NVD link : CVE-2025-63729

Mitre link : CVE-2025-63729

CVE.ORG link : CVE-2025-63729


JSON object : View

Products Affected

syrotech

  • sy-gpon-1110-wdont
  • sy-gpon-1110-wdont_firmware
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-312

Cleartext Storage of Sensitive Information

CWE-532

Insertion of Sensitive Information into Log File