CVE-2024-36475

EUVD-2024-36112
FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug code vulnerability. If a user who knows how to use the debug function logs in to the product, the debug function may be used and an arbitrary OS command may be executed.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
Affected Products (NVD)
VendorProductVersion
centurysysfuturenet_nxr-1300_firmware
𝑥
< 7.4.10
centurysysfuturenet_nxr-155\/c_firmware
*
centurysysfuturenet_nxr-610x_firmware
𝑥
< 21.14.11c
centurysysfuturenet_nxr-g050_firmware
𝑥
< 21.12.10
centurysysfuturenet_nxr-g060_firmware
𝑥
< 21.15.6
centurysysfuturenet_nxr-g100_firmware
𝑥
< 6.23.11
centurysysfuturenet_nxr-g110_firmware
𝑥
< 21.7.32
centurysysfuturenet_nxr-g120_firmware
𝑥
< 21.15.2c
centurysysfuturenet_nxr-g200_firmware
𝑥
< 9.12.16
centurysysfuturenet_vxr-x64
𝑥
< 21.7.32
centurysysfuturenet_vxr-x86
𝑥
< 10.1.5
centurysysfuturenet_nxr-160\/lw_firmware
𝑥
< 21.8.4
centurysysfuturenet_nxr-230\/c_firmware
𝑥
< 5.30.13
centurysysfuturenet_nxr-350\/c_firmware
𝑥
< 5.30.9c
centurysysfuturenet_nxr-530_firmware
𝑥
< 21.11.14
centurysysfuturenet_nxr-650_firmware
𝑥
< 21.16.2
centurysysfuturenet_nxr-g180\/l-ca_firmware
𝑥
< 21.7.28c
centurysysfuturenet_nxr-130\/c_firmware
*
centurysysfuturenet_nxr-125\/cx_firmware
*
centurysysfuturenet_nxr-120\/c_firmware
*
centurysysfuturenet_wxr-250_firmware
*
centurysysfuturenet_nxr-1200_firmware
*
𝑥
= Vulnerable software versions