CVE-2024-46658
nicheAuthenticated Command Injection (RCE) in Syrotech SY-GOPON-8OLT-L3
Syrotech's SY-GOPON-8OLT-L3, an optical line terminal (OLT) used in fiber access networks, running firmware v1.6.0_240629 contains an authenticated OS command injection flaw (CWE-78). An attacker with valid low-privileged credentials on the device's management interface can inject shell commands into a vulnerable parameter, which the system then executes; the CVSS vector (AV:A/PR:L) indicates the attacker needs adjacent network access to the management plane plus a valid login. Successful exploitation yields arbitrary command execution with high confidentiality, integrity, and availability impact, effectively full compromise of the OLT and a potential foothold to pivot into the operator's management or access network. Any operator running this model on the cited firmware is affected; other firmware versions have not been formally assessed in the available data. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, although the elevated EPSS score (24.4% probability of exploitation within 30 days, 98th percentile) suggests a materially increased risk of exploitation in the near term.
What to do: Inventory deployed SY-GOPON-8OLT-L3 units and check firmware versions; if running v1.6.0_240629, contact Syrotech for a patched release (no fixed version is documented in the available data) and, until then, restrict the management interface to a dedicated management VLAN, enforce strong credentials on all accounts including low-privileged ones, and avoid exposing the web UI to the internet. Because exploitation requires only low-privileged credentials, treat all management accounts as capable of full device compromise until a fix is applied.
| Syrotech SY-GOPON-8OLT-L3 (optical line terminal, fiber access) | v1.6.0_240629 (version cited as affected; no other version ranges documented in available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.