ZeroHour

CVE-2024-46658

niche

Authenticated Command Injection (RCE) in Syrotech SY-GOPON-8OLT-L3

CVSS 3.1
8.0 high
EPSS
24%p98
Published
()
Modified
AI analysis

Syrotech's SY-GOPON-8OLT-L3, an optical line terminal (OLT) used in fiber access networks, running firmware v1.6.0_240629 contains an authenticated OS command injection flaw (CWE-78). An attacker with valid low-privileged credentials on the device's management interface can inject shell commands into a vulnerable parameter, which the system then executes; the CVSS vector (AV:A/PR:L) indicates the attacker needs adjacent network access to the management plane plus a valid login. Successful exploitation yields arbitrary command execution with high confidentiality, integrity, and availability impact, effectively full compromise of the OLT and a potential foothold to pivot into the operator's management or access network. Any operator running this model on the cited firmware is affected; other firmware versions have not been formally assessed in the available data. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, although the elevated EPSS score (24.4% probability of exploitation within 30 days, 98th percentile) suggests a materially increased risk of exploitation in the near term.

What to do: Inventory deployed SY-GOPON-8OLT-L3 units and check firmware versions; if running v1.6.0_240629, contact Syrotech for a patched release (no fixed version is documented in the available data) and, until then, restrict the management interface to a dedicated management VLAN, enforce strong credentials on all accounts including low-privileged ones, and avoid exposing the web UI to the internet. Because exploitation requires only low-privileged credentials, treat all management accounts as capable of full device compromise until a fix is applied.

Affected
Syrotech SY-GOPON-8OLT-L3 (optical line terminal, fiber access)v1.6.0_240629 (version cited as affected; no other version ranges documented in available data)
Estimated exposure
nichelikely hundreds to low thousands of deployed units (est.) — Single OLT SKU from a regional, India-focused fiber-access vendor typically sold in small unit counts to small ISPs and campus networks, with no public internet-exposure scan counts available for this device, so the figure is inferred from…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability.

Weakness
CWE-78
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.