CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-36491

Medium Severity
Centurysys
SVRS
30/100

CVSSv3
9.8/10

EPSS
0.00489/1

CVE-2024-36491 is a critical vulnerability in Century Systems Co., Ltd.'s FutureNet NXR, VXR, and WXR series, enabling arbitrary OS command execution by administrative users. This flaw allows attackers to obtain or alter sensitive information, leading to a denial-of-service (DoS) condition. Despite a high CVSS score of 9.8, the SOCRadar Vulnerability Risk Score (SVRS) is 30, suggesting a lower immediate risk level compared to other vulnerabilities. However, given the potential for sensitive data compromise and DoS, patching remains crucial. The root cause, CWE-78, indicates improper neutralization of special elements used in an OS command. This vulnerability is significant because it can allow a malicious administrator to fully compromise affected devices.

In The Wild
CVSS:3.1
AV:N
AC:L
PR:N
UI:N
S:U
C:H
I:H
A:H
2025-04-08

2024-07-17

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-36491 | Century Systems FutureNet WXR-250 os command injection
vuldb.com2024-07-17
CVE-2024-36491 | Century Systems FutureNet WXR-250 os command injection | A vulnerability classified as critical was found in Century Systems FutureNet NXR-1300, FutureNet NXR-650, FutureNet NXR-610X, FutureNet NXR-530, FutureNet NXR-350, C, FutureNet NXR-230, FutureNet NXR-160, LW, FutureNet NXR-G200, FutureNet NXR-G180, L-CA, FutureNet NXR-G120, FutureNet NXR-G110, FutureNet NXR-G100, FutureNet NXR-G060, FutureNet NXR-G050, FutureNet VXR, x64, x86, FutureNet NXR-1200, FutureNet NXR-130, FutureNet NXR-155, FutureNet NXR-125
rss
cves
cve-2024-36491
domains

Social Media

A series of critical flaws have been identified in FutureNet's NXR, VXR, and WXR series networking devices. CVE-2024-31070, CVE-2024-36475, CVE-2024-36491, and CVE-2020-10188, range in severity with CVSS scores reaching 9.8 https://t.co/s1G52IWDNm
0
0
0

Affected Software

Configuration 1
TypeVendorProduct
OSCenturysysfuturenet_nxr-g050_firmware
OSCenturysysfuturenet_nxr-g200_firmware
OSCenturysysfuturenet_nxr-g100_firmware
OSCenturysysfuturenet_nxr-g110_firmware
OSCenturysysfuturenet_vxr-x64
OSCenturysysfuturenet_nxr-1300_firmware
OSCenturysysfuturenet_vxr-x86
OSCenturysysfuturenet_nxr-610x_firmware
OSCenturysysfuturenet_nxr-155\/c_firmware
OSCenturysysfuturenet_nxr-g060_firmware
Configuration 5
TypeVendorProduct
OSCenturysysfuturenet_nxr-530_firmware
Configuration 6
TypeVendorProduct
OSCenturysysfuturenet_nxr-650_firmware
Configuration 8
TypeVendorProduct
OSCenturysysfuturenet_nxr-130\/c_firmware
Configuration 9
TypeVendorProduct
OSCenturysysfuturenet_nxr-125\/cx_firmware
Configuration 10
TypeVendorProduct
OSCenturysysfuturenet_nxr-120\/c_firmware
Configuration 11
TypeVendorProduct
OSCenturysysfuturenet_wxr-250_firmware
Configuration 12
TypeVendorProduct
OSCenturysysfuturenet_nxr-1200_firmware

References

ReferenceLink
[email protected]https://jvn.jp/en/vu/JVNVU96424864/
[email protected]https://www.centurysys.co.jp/backnumber/nxr_common/20240716-01.html
[email protected]https://www.centurysys.co.jp/backnumber/nxr_common/20240716-03.html
AF854A3A-2127-422B-91AE-364DA2661108https://jvn.jp/en/vu/JVNVU96424864/
AF854A3A-2127-422B-91AE-364DA2661108https://www.centurysys.co.jp/backnumber/nxr_common/20240716-01.html
AF854A3A-2127-422B-91AE-364DA2661108https://www.centurysys.co.jp/backnumber/nxr_common/20240716-03.html
[email protected]https://jvn.jp/en/vu/JVNVU96424864/
[email protected]https://www.centurysys.co.jp/backnumber/nxr_common/20240716-01.html
[email protected]https://www.centurysys.co.jp/backnumber/nxr_common/20240716-03.html

CWE Details

CWE IDCWE NameDescription
CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence