CVE-2024-36491

FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allow an administrative user to execute an arbitrary OS command, obtain and/or alter sensitive information, and cause a denial-of-service (DoS) condition.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
jpcertCNA
---
---
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
VendorProductVersion
centurysysfuturenet_nxr-1300_firmware
𝑥
< 7.4.10
centurysysfuturenet_nxr-155\/c_firmware
*
centurysysfuturenet_nxr-610x_firmware
𝑥
< 21.14.11c
centurysysfuturenet_nxr-g050_firmware
𝑥
< 21.12.10
centurysysfuturenet_nxr-g060_firmware
𝑥
< 21.15.6
centurysysfuturenet_nxr-g100_firmware
𝑥
< 6.23.11
centurysysfuturenet_nxr-g110_firmware
𝑥
< 21.7.32
centurysysfuturenet_nxr-g120_firmware
𝑥
< 21.15.2c
centurysysfuturenet_nxr-g200_firmware
𝑥
< 9.12.16
centurysysfuturenet_vxr-x64
𝑥
< 21.7.32
centurysysfuturenet_vxr-x86
𝑥
< 10.1.5
centurysysfuturenet_nxr-160\/lw_firmware
𝑥
< 21.8.4
centurysysfuturenet_nxr-230\/c_firmware
𝑥
< 5.30.13
centurysysfuturenet_nxr-350\/c_firmware
𝑥
< 5.30.9c
centurysysfuturenet_nxr-530_firmware
𝑥
< 21.11.14
centurysysfuturenet_nxr-650_firmware
𝑥
< 21.16.2
centurysysfuturenet_nxr-g180\/l-ca_firmware
𝑥
< 21.7.28c
centurysysfuturenet_nxr-130\/c_firmware
*
centurysysfuturenet_nxr-125\/cx_firmware
*
centurysysfuturenet_nxr-120\/c_firmware
*
centurysysfuturenet_wxr-250_firmware
*
centurysysfuturenet_nxr-1200_firmware
*
𝑥
= Vulnerable software versions