Insecure Default Vulnerability in Century Systems' Products Allows Unlimited Telnet Access
CVE-2024-31070

9.1CRITICAL

What is CVE-2024-31070?

The vulnerability involves the initialization of resources with an insecure default in the FutureNet NXR, VXR, and WXR series products developed by Century Systems Co., Ltd. This oversight allows remote unauthenticated attackers to gain unlimited access to the telnet service. The potential exploitation of this vulnerability poses significant security risks, facilitating unauthorized control and manipulation of the affected devices.

Affected Version(s)

FutureNet NXR-120/C firmware version 5.25.7H and earlier

FutureNet NXR-1200 firmware version 5.25.21 and earlier

FutureNet NXR-125/CX firmware version 5.25.7H and earlier

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.