[CIVN-2025-0223] Unrestricted FTP Access Vulnerability In Syrotech Router

By Published On: September 25, 2025

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Unrestricted FTP Access Vulnerability In Syrotech Router 
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Systems Affected
Syrotech SY-GPON-2010-WADONT, firmware version V2.1.05-210329
Overview
A vulnerability has been reported in SY-GPON-2010-WADONT Router, which could allow an attacker to access sensitive information on targeted device.
Target Audience:
End-users/ Administrators of SY-GPON-2010-WADONT Router.
Risk Assessment:
Unrestricted access to sensitive system files and configuration files on the targeted device.
Impact Assessment:
Impact on confidentiality, integrity and availability of the vulnerable device.
Description
The Syrotech SY-GPON-2010-WADONT is a dual-band XPON Optical Network Terminal (ONT) designed for Fiber-to-the-Home (FTTH) deployments, supporting both GPON and EPON standards. It provides integrated routing, Wi-Fi connectivity, and a voice port for broadband, VoIP, and IPTV services.
This vulnerability exists in the SY-GPON-2010-WADONT router due to improper access control in its FTP service. A remote attacker could exploit this vulnerability by establishing an FTP connection using default credentials, potentially gaining unauthorized access to configuration files, user credentials, or other sensitive information stored on the targeted device.
Credit
This vulnerability is reported by Jahit Hoque.
Solution
Upgrade Syrotech SY-GPON-2010-WADONT router to firmware version V2.1.08-241213
https://www.syrotech.com/firmwares/
Vendor Information
Syrotech Networks
https://www.syrotech.com/firmwares/
References
Syrotech Networks
https://www.syrotech.com/firmwares/
CVE Name
CVE-2024-10957
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmjVWUUACgkQ3jCgcSdc
ys/BCxAAkmmgpDKyf/YI3wZm7aHtcVAdArQT3XuC3+yRLOk5P0aW1zvpCyrYoh7h
FKe8UfwzBJPzhcR0VqFsvTIew6f+oKIfxGgThmEqs2K2bfGdoRA5PeIWcFiZ72DL
zjZFDKBPtIJv94ecJWXOao6iXwvZbpgIUaqjszdrtwtzieZRZitHToDrhEfw+o7L
a5qAEFeZ7Vqr7CRzhnPvIhQYumFB8Wq/J5rDDY+kwoLRu2x9tWBu6sTZuc0q/ra6
rhNYSgAUbvA8FyJV+YS5NL8NsCcFqcNvzpJZDjJmN20FKIqCfnMFveDJSGdBzojN
Ye3GwbPu6gneGeNvj4UKMBfp90sLQ8M79cjbHsXk4gGnSiNyIj66HSG6h1amYKYG
8b+4gqw5PIfJ0tq7wc2zC/U0Bu2//fZY3kMxYO1wg+6T4F1ssoT+O7GVCS7ufa+I
rGZ9ls8KYTSz+zHCfJ8w4aRfnfJg6KYK8XsKoBP3LyE8s7WBcFjkMiJSgNutbNjT
p3JfBRc9ZCWSAKg8AejNEVzVhODJhFXuw5HyliXUQdBAQ1RF2U/aZdM6oeZ9YhTO
4JQjFAEkA6QsFsE8aW7dFvWKZ6BLtBBr4bLGa1IU7ogWh+WuLLvlcR7y3RNtx7U8
SVFcAA0xDVr4n+p1tJOwfjTEqnKCL6LUex7NuyDw/3bznMKA5co=
=RoNa
—–END PGP SIGNATURE—–

Share this article