CVE-2025-63729
critical · 9An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SSL Certificate, and Client Certificates in .pem format in firmware in etc folder.
9
CVSS
0.1%
EPSS (exploit prob.)
0th
EPSS percentile
2025-11-25
Published
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Weaknesses
CWE-200CWE-312CWE-532
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| syrotech | sy-gpon-1110-wdont_firmware | 3.1.02-240517 |
| syrotech | sy-gpon-1110-wdont | 3.7l |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-63729