← All CVEs

CVE-2025-63729

critical · 9

An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SSL Certificate, and Client Certificates in .pem format in firmware in etc folder.

9
CVSS
0.1%
EPSS (exploit prob.)
0th
EPSS percentile
2025-11-25
Published

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Weaknesses

CWE-200CWE-312CWE-532

Affected products

VendorProductAffected versions
syrotechsy-gpon-1110-wdont_firmware3.1.02-240517
syrotechsy-gpon-1110-wdont3.7l

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-63729