CVE-2024-36491

CRITICALCVSS 9.8/10EPSS 0.65%

Last modified

CVE-2024-36491 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allow an administrative user to execute an arbitrary OS command, obtain and/or alter sensitive information, and cause a denial-of-service (DoS) condition.. EPSS estimates a 0.65% chance of exploitation in the next 30 days.

Description

FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allow an administrative user to execute an arbitrary OS command, obtain and/or alter sensitive information, and cause a denial-of-service (DoS) condition.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.65%

46.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CenturysysFuturenet Nxr-1300 Firmware< 7.4.10
CenturysysFuturenet Nxr-155\/C FirmwareAll versions
CenturysysFuturenet Nxr-610x Firmware< 21.14.11c
CenturysysFuturenet Nxr-G050 Firmware< 21.12.10
CenturysysFuturenet Nxr-G060 Firmware< 21.15.6
CenturysysFuturenet Nxr-G100 Firmware< 6.23.11
CenturysysFuturenet Nxr-G110 Firmware< 21.7.32
CenturysysFuturenet Nxr-G120 Firmware< 21.15.2c
CenturysysFuturenet Nxr-G200 Firmware< 9.12.16
CenturysysFuturenet Vxr-X64< 21.7.32
CenturysysFuturenet Vxr-X86< 10.1.5
CenturysysFuturenet Nxr-160\/Lw Firmware< 21.8.4
CenturysysFuturenet Nxr-230\/C Firmware< 5.30.13
CenturysysFuturenet Nxr-350\/C Firmware< 5.30.9c
CenturysysFuturenet Nxr-530 Firmware< 21.11.14
CenturysysFuturenet Nxr-650 Firmware< 21.16.2
CenturysysFuturenet Nxr-G180\/L-Ca Firmware< 21.7.28c
CenturysysFuturenet Nxr-130\/C FirmwareAll versions
CenturysysFuturenet Nxr-125\/Cx FirmwareAll versions
CenturysysFuturenet Nxr-120\/C FirmwareAll versions
CenturysysFuturenet Wxr-250 FirmwareAll versions
CenturysysFuturenet Nxr-1200 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2024-36491?
FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allow an administrative user to execute an arbitrary OS command, obtain and/or alter sensitive information, and cause a denial-of-service (DoS) condition.
How severe is CVE-2024-36491?
CVE-2024-36491 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 0.65% probability of exploitation in the next 30 days.
How do I fix CVE-2024-36491?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2024-36491?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST