CVE-2024-41692
Description
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the root shell on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary commands with root privileges on the targeted system.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2024-41692? +
How do I check if I'm vulnerable to CVE-2024-41692? +
Related Vulnerabilities
On-Chip Debug and Test Interface With Improper Access Control and Improper Protection against Electromagnetic Fault Injection (EM-FI) in Nordic Semiconductor …
The CleverDisplay BlueOne hardware player is designed with its USB interfaces physically enclosed and inaccessible under normal operating conditions. Researchers …
The ventilator's microcontroller lacks memory protection. An attacker could connect to the internal JTAG interface and read or write to …
As UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump …
On-chip debug and test interface with improper access control in some 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX …
A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the …