CVE Feed

    Dashboard / CVE / CVE-2024-50357

    CVE-2024-50357

    FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in the initial (factory default) configuration. But, REST-APIs are unexpectedly enabled when the affected product is powered up, provided either http-server (GUI) or Web authentication is enabled. The factory default configuration makes http-server (GUI) enabled, which means REST-APIs are also enabled. The username and the password for REST-APIs are configured in the factory default configuration. As a result, an attacker may obtain and/or alter the affected product's settings via REST-APIs.

    Published:Nov 29, 2024
    Last Modified:Apr 15, 2026
    EPS:Nov 29, 2024
    EPSS Score:0.00141
    CVSS Score:9.8

    Affected Products

    Vendor
    Centurysys
    Product
    Futurenet Nxr-g050 Firmware
    Vendor
    Centurysys
    Product
    Futurenet Nxr-g060 Firmware
    Vendor
    Centurysys
    Product
    Futurenet Nxr-g110 Firmware

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High