Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2024-50357
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in the initial (factory default) configuration. But, REST-APIs are unexpectedly enabled when the affected product is powered up, provided either http-server (GUI) or Web authentication is enabled. The factory default configuration makes http-server (GUI) enabled, which means REST-APIs are also enabled. The username and the password for REST-APIs are configured in the factory default configuration. As a result, an attacker may obtain and/or alter the affected product's settings via REST-APIs.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
特定函数功能的不正确供给
Source: NVD (National Vulnerability Database)
Vulnerability Title
Century Systems FutureNet NXR 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Century Systems FutureNet NXR是日本Century Systems公司的一系列路由器。 Century Systems FutureNet NXR存在安全漏洞,该漏洞源于初始配置中REST-APIs在设备启动时意外启用,攻击者可能通过REST-API获取或更改受影响产品的设置。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
Century Systems Co., Ltd.FutureNet NXR-G110 series firmware versions 21.15.7 and later but prior to 21.15.9 -
Century Systems Co., Ltd.FutureNet NXR-G060 series firmware versions prior to 21.15.6C1 -
Century Systems Co., Ltd.FutureNet NXR-G050 series firmware versions 21.12.5 and later but prior to 21.12.11 -
II. Public POCs for CVE-2024-50357
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2024-50357
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2024-50357

No comments yet


Leave a comment