CVE-2024-36475

FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug code vulnerability. If a user who knows how to use the debug function logs in to the product, the debug function may be used and an arbitrary OS command may be executed.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
jpcertCNA
---
---
CISA-ADPADP
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
VendorProductVersion
centurysysfuturenet_nxr-1300_firmware
𝑥
< 7.4.10
centurysysfuturenet_nxr-155\/c_firmware
*
centurysysfuturenet_nxr-610x_firmware
𝑥
< 21.14.11c
centurysysfuturenet_nxr-g050_firmware
𝑥
< 21.12.10
centurysysfuturenet_nxr-g060_firmware
𝑥
< 21.15.6
centurysysfuturenet_nxr-g100_firmware
𝑥
< 6.23.11
centurysysfuturenet_nxr-g110_firmware
𝑥
< 21.7.32
centurysysfuturenet_nxr-g120_firmware
𝑥
< 21.15.2c
centurysysfuturenet_nxr-g200_firmware
𝑥
< 9.12.16
centurysysfuturenet_vxr-x64
𝑥
< 21.7.32
centurysysfuturenet_vxr-x86
𝑥
< 10.1.5
centurysysfuturenet_nxr-160\/lw_firmware
𝑥
< 21.8.4
centurysysfuturenet_nxr-230\/c_firmware
𝑥
< 5.30.13
centurysysfuturenet_nxr-350\/c_firmware
𝑥
< 5.30.9c
centurysysfuturenet_nxr-530_firmware
𝑥
< 21.11.14
centurysysfuturenet_nxr-650_firmware
𝑥
< 21.16.2
centurysysfuturenet_nxr-g180\/l-ca_firmware
𝑥
< 21.7.28c
centurysysfuturenet_nxr-130\/c_firmware
*
centurysysfuturenet_nxr-125\/cx_firmware
*
centurysysfuturenet_nxr-120\/c_firmware
*
centurysysfuturenet_wxr-250_firmware
*
centurysysfuturenet_nxr-1200_firmware
*
𝑥
= Vulnerable software versions