CVE-2024-36491
Centurysys
CVE-2024-36491 is a critical vulnerability in Century Systems Co., Ltd.'s FutureNet NXR, VXR, and WXR series, enabling arbitrary OS command execution by administrative users. This flaw allows attackers to obtain or alter sensitive information, leading to a denial-of-service (DoS) condition. Despite a high CVSS score of 9.8, the SOCRadar Vulnerability Risk Score (SVRS) is 30, suggesting a lower immediate risk level compared to other vulnerabilities. However, given the potential for sensitive data compromise and DoS, patching remains crucial. The root cause, CWE-78, indicates improper neutralization of special elements used in an OS command. This vulnerability is significant because it can allow a malicious administrator to fully compromise affected devices.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.