Possible Remote Attack Vulnerabilities in FutureNet NXR, VXR, and WXR Series Devices
CVE-2024-36491

9.8CRITICAL

What is CVE-2024-36491?

A vulnerability in the FutureNet NXR, VXR, and WXR series products from Century Systems Co., Ltd. allows an unauthenticated remote attacker to execute arbitrary operating system commands. This flaw enables the attacker to access and potentially alter sensitive information stored on the affected devices. Moreover, it presents opportunities for attackers to induce a denial of service condition, disrupting the normal functionality of the impacted systems. Organizations utilizing these products should implement security measures and patches to mitigate exposure to this vulnerability.

Affected Version(s)

FutureNet NXR-120/C firmware version 5.25.7H and earlier

FutureNet NXR-1200 firmware version 5.25.21 and earlier

FutureNet NXR-125/CX firmware version 5.25.7H and earlier

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.