CVE-2025-63729CRITICAL 9.0EPSS p0.2%

CVE-2025-63729CVE-2025-63729

Description

An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SSL Certificate, and Client Certificates in .pem format in firmware in etc folder.

Scoring

CVSS 3.19.0 (CRITICAL)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
EPSS0.08% probability of exploitation · percentile 0.2% · 2026-06-18T12:00:27Z
Published2025-11-25
Last modified2025-12-30

Underlying weaknesses· 3

CWE-200CWE-312CWE-532

References

  1. https://github.com/Yashodhanvivek/CVE-2025-63729-Syrotech-SY-GPON-1110-/blob/main/Syrotech_SY-GPON-1110-WDONT_Security_Assessment.pdf

3

TypeTargetConfidenceTier
WeaknessExposure of Sensitive Information to an Unauthorized Actorcwe-2000%live
WeaknessCleartext Storage of Sensitive Informationcwe-3120%live
WeaknessInsertion of Sensitive Information into Log Filecwe-5320%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-63409
CVE
CVE-2025-56577
CVE
CVE-2025-41659
CVE
CVE-2026-45433
CVE
CVE-2025-67112
CVE
CVE-2025-9146
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.