SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-36475

FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug code vulnerability.

HIGH 8.8EPSS 0.62%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.62%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug code vulnerability. If a user who knows how to use the debug function logs in to the product, the debug function may be used and an arbitrary OS command may be executed.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.62% probability · 48th percentile
CISA KEV
Not listed
Weakness
CWE-78, CWE-489
Affected
centurysys/futurenet nxr-1300 firmware · centurysys/futurenet nxr-155\/c firmware · centurysys/futurenet nxr-610x firmware · centurysys/futurenet nxr-g050 firmware · centurysys/futurenet nxr-g060 firmware · centurysys/futurenet nxr-g100 firmware · centurysys/futurenet nxr-g110 firmware · centurysys/futurenet nxr-g120 firmware · centurysys/futurenet nxr-g200 firmware · centurysys/futurenet vxr-x64 · centurysys/futurenet vxr-x86 · centurysys/futurenet nxr-160\/lw firmware · centurysys/futurenet nxr-230\/c firmware · centurysys/futurenet nxr-350\/c firmware · centurysys/futurenet nxr-530 firmware · centurysys/futurenet nxr-650 firmware · centurysys/futurenet nxr-g180\/l-ca firmware · centurysys/futurenet nxr-130\/c firmware · centurysys/futurenet nxr-125\/cx firmware · centurysys/futurenet nxr-120\/c firmware · +2 more
Source
vultures@jpcert.or.jp

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.