CRITICAL · 9.1

CVE-2024-31070

Initialization of a resource with an insecure default vulnerability in FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allows a remote unauthenticated attacker to...

Vulnerability Description

Initialization of a resource with an insecure default vulnerability in FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allows a remote unauthenticated attacker to access telnet service unlimitedly.

CVSS Score

9.1

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
CenturysysFuturenet Nxr-1300 Firmware< 7.4.10
CenturysysFuturenet Nxr-155\/C FirmwareAll versions
CenturysysFuturenet Nxr-610X Firmware< 21.14.11c
CenturysysFuturenet Nxr-G050 Firmware< 21.12.10
CenturysysFuturenet Nxr-G060 Firmware< 21.15.6
CenturysysFuturenet Nxr-G100 Firmware< 6.23.11
CenturysysFuturenet Nxr-G110 Firmware< 21.7.32
CenturysysFuturenet Nxr-G120 Firmware< 21.15.2c
CenturysysFuturenet Nxr-G200 Firmware< 9.12.16
CenturysysFuturenet Vxr-X64< 21.7.32
CenturysysFuturenet Vxr-X86< 10.1.5
CenturysysFuturenet Nxr-160\/Lw Firmware< 21.8.4
CenturysysFuturenet Nxr-160\/Lw-
CenturysysFuturenet Nxr-230\/C Firmware< 5.30.13
CenturysysFuturenet Nxr-230\/C-
CenturysysFuturenet Nxr-350\/C Firmware< 5.30.9c
CenturysysFuturenet Nxr-350\/C-
CenturysysFuturenet Nxr-530 Firmware< 21.11.14
CenturysysFuturenet Nxr-530-
CenturysysFuturenet Nxr-650 Firmware< 21.16.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-31070?

CVE-2024-31070 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Initialization of a resource with an insecure default vulnerability in FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allows a remote unauthenticated attacker to...

How severe is CVE-2024-31070?

CVE-2024-31070 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2024-31070?

Check the references section above for vendor advisories and patch information. Affected products include: Centurysys Futurenet Nxr-1300 Firmware, Centurysys Futurenet Nxr-155\/C Firmware, Centurysys Futurenet Nxr-610X Firmware, Centurysys Futurenet Nxr-G050 Firmware, Centurysys Futurenet Nxr-G060 Firmware.