Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-45180 | FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in the initial (factory default) configuration. But, REST-APIs are unexpectedly enabled when the affected product is powered up, provided either http-server (GUI) or Web authentication is enabled. The factory default configuration makes http-server (GUI) enabled, which means REST-APIs are also enabled. The username and the password for REST-APIs are configured in the factory default configuration. As a result, an attacker may obtain and/or alter the affected product's settings via REST-APIs. |
Mon, 02 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Centurysys
Centurysys futurenet Nxr-g050 Firmware Centurysys futurenet Nxr-g060 Firmware Centurysys futurenet Nxr-g110 Firmware |
|
| CPEs | cpe:2.3:o:centurysystems:futurenet_nxr-g060_series_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:centurysystems:futurenet_nxr-g110_series_firmware:*:*:*:*:*:*:*:* |
cpe:2.3:o:centurysys:futurenet_nxr-g050_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:centurysys:futurenet_nxr-g060_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:centurysys:futurenet_nxr-g110_firmware:*:*:*:*:*:*:*:* |
| Vendors & Products |
Centurysystems
Centurysystems futurenet Nxr-g050 Series Firmware Centurysystems futurenet Nxr-g060 Series Firmware Centurysystems futurenet Nxr-g110 Series Firmware |
Centurysys
Centurysys futurenet Nxr-g050 Firmware Centurysys futurenet Nxr-g060 Firmware Centurysys futurenet Nxr-g110 Firmware |
Fri, 29 Nov 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Centurysystems
Centurysystems futurenet Nxr-g050 Series Firmware Centurysystems futurenet Nxr-g060 Series Firmware Centurysystems futurenet Nxr-g110 Series Firmware |
|
| CPEs | cpe:2.3:o:centurysystems:futurenet_nxr-g050_series_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:centurysystems:futurenet_nxr-g060_series_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:centurysystems:futurenet_nxr-g110_series_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Centurysystems
Centurysystems futurenet Nxr-g050 Series Firmware Centurysystems futurenet Nxr-g060 Series Firmware Centurysystems futurenet Nxr-g110 Series Firmware |
|
| Metrics |
ssvc
|
Fri, 29 Nov 2024 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in the initial (factory default) configuration. But, REST-APIs are unexpectedly enabled when the affected product is powered up, provided either http-server (GUI) or Web authentication is enabled. The factory default configuration makes http-server (GUI) enabled, which means REST-APIs are also enabled. The username and the password for REST-APIs are configured in the factory default configuration. As a result, an attacker may obtain and/or alter the affected product's settings via REST-APIs. | |
| Weaknesses | CWE-684 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-12-02T18:15:27.594Z
Reserved: 2024-10-23T04:47:33.910Z
Link: CVE-2024-50357
Updated: 2024-11-29T13:32:08.712Z
Status : Deferred
Published: 2024-11-29T10:15:10.833
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-50357
No data.
OpenCVE Enrichment
No data.
EUVD