VDB

JVNDB-2024-004595

JVNDB-2024-004595 PUBLISHED

FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain multiple vulnerabilities listed below. * Initialization of a Resource with an Insecure Default (CWE-1188) - CVE-2024-31070 * Active Debug Code (CWE-489) - CVE-2024-36475 * OS Command Injection (CWE-78) - CVE-2024-36491 * Buffer Overflow (CWE-120) - CVE-2020-10188 The product uses previous versions of netkit-telnet which contains a known vulnerability. CVE-2024-31070, CVE-2024-36475 Katsuhiko Sato(a.k.a. goroh_kun) of 00One, Inc. reported these vulnerabilities to JPCERT/CC. JPCERT/CC coordinated with the developer. CVE-2024-36491, CVE-2020-10188 Century Systems Co., Ltd. reported these vulnerabilities to JPCERT/CC to notify users of its solution through JVN.

Timeline

  • Mar 6, 2020 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›