Authentication Bypass in FutureNet AS Series Industrial Routers by Century Systems Co., Ltd.
CVE-2025-24846

7.5HIGH

What is CVE-2025-24846?

An authentication bypass vulnerability exists in the FutureNet AS Series industrial routers manufactured by Century Systems Co., Ltd. This security flaw could empower a remote, unauthenticated attacker to gain access to sensitive device information, such as the MAC address, by sending carefully crafted requests. It highlights the importance of securing industrial devices and implementing strong authentication measures to prevent unauthorized access.

Affected Version(s)

FutureNet AS-210/U4 firmware Version 2.6.4 and earlier

FutureNet AS-250/F-KO firmware Version 1.14.0 and earlier

FutureNet AS-250/F-SC firmware Version 1.14.0 and earlier

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.