// For flags

CVE-2024-36491

 

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allow a remote unauthenticated attacker to execute an arbitrary OS command, obtain and/or alter sensitive information, and be able to cause a denial of service (DoS) condition.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
None
Automatable
Yes
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2024-06-06 CVE Reserved
  • 2024-07-17 CVE Published
  • 2024-08-02 CVE Updated
  • 2024-09-28 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet NXR-1300 Series
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-1300 Series"
7.4.9
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-1300 Series" and version "7.4.9"
en
Affected
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet NXR-650
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-650"
21.16.1
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-650" and version "21.16.1"
en
Affected
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet NXR-610X Series
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-610X Series"
21.14.11
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-610X Series" and version "21.14.11"
en
Affected
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet NXR-530
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-530"
21.11.13
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-530" and version "21.11.13"
en
Affected
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet NXR-350/C
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-350/C"
5.30.9
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-350/C" and version "5.30.9"
en
Affected
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet NXR-230/C
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-230/C"
5.30.12
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-230/C" and version "5.30.12"
en
Affected
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet NXR-160/LW
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-160/LW"
21.8.3
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-160/LW" and version "21.8.3"
en
Affected
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet NXR-G200 Series
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-G200 Series"
9.12.15
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-G200 Series" and version "9.12.15"
en
Affected
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet NXR-G180/L-CA
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-G180/L-CA"
21.7.28
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-G180/L-CA" and version "21.7.28"
en
Affected
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet NXR-G120 Series
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-G120 Series"
21.15.2
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-G120 Series" and version "21.15.2"
en
Affected
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet NXR-G110 Series
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-G110 Series"
21.7.30
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-G110 Series" and version "21.7.30"
en
Affected
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet NXR-G100 Series
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-G100 Series"
6.23.10
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-G100 Series" and version "6.23.10"
en
Affected
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet NXR-G060 Series
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-G060 Series"
21.15.5
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-G060 Series" and version "21.15.5"
en
Affected
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet NXR-G050 Series
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-G050 Series"
21.12.9
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-G050 Series" and version "21.12.9"
en
Affected
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet VXR/x64
Search vendor "Century Systems Co., Ltd." for product "FutureNet VXR/x64"
21.7.31
Search vendor "Century Systems Co., Ltd." for product "FutureNet VXR/x64" and version "21.7.31"
en
Affected
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet VXR/x86
Search vendor "Century Systems Co., Ltd." for product "FutureNet VXR/x86"
10.1.4
Search vendor "Century Systems Co., Ltd." for product "FutureNet VXR/x86" and version "10.1.4"
en
Affected
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet NXR-1200
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-1200"
5.25.21
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-1200" and version "5.25.21"
en
Affected
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet NXR-130/C
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-130/C"
5.13.21
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-130/C" and version "5.13.21"
en
Affected
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet NXR-155/C Series
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-155/C Series"
5.22.5
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-155/C Series" and version "5.22.5"
en
Affected
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet NXR-125/CX
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-125/CX"
5.25.7
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-125/CX" and version "5.25.7"
en
Affected
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet NXR-120/C
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-120/C"
5.25.7
Search vendor "Century Systems Co., Ltd." for product "FutureNet NXR-120/C" and version "5.25.7"
en
Affected
Century Systems Co., Ltd.
Search vendor "Century Systems Co., Ltd."
FutureNet WXR-250
Search vendor "Century Systems Co., Ltd." for product "FutureNet WXR-250"
1.4.7
Search vendor "Century Systems Co., Ltd." for product "FutureNet WXR-250" and version "1.4.7"
en
Affected