Vulnerabilities > Syrotech > High

DATE CVE VULNERABILITY TITLE RISK
2024-07-26 CVE-2024-41685 Incorrect Permission Assignment for Critical Resource vulnerability in Syrotech Sy-Gpon-1110-Wdont Firmware 3.1.02231102
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web management interface.
network
low complexity
syrotech CWE-732
7.5
2024-07-26 CVE-2024-41687 Cleartext Transmission of Sensitive Information vulnerability in Syrotech Sy-Gpon-1110-Wdont Firmware 3.1.02231102
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text.
network
low complexity
syrotech CWE-319
7.5