Initialization of a resource with an insecure default vulnerability in FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allows a remote unauthenticated attacker to access telnet service unlimitedly.
The vulnerability results from the use of insecure default settings during resource initialization (CWE-1188). The Telnet service on the device does not require authentication or its access control mechanism is configured to allow unrestricted connections. A remote, unauthenticated attacker can connect to the Telnet service over the network without providing any login credentials, completely bypassing authentication mechanisms.
Attackers gain unrestricted access to the device's Telnet service, which can lead to takeover of network device configuration control and disclosure of confidential configuration data. This can result in violation of confidentiality and availability of the entire network infrastructure served by the device.
Security patches available from the manufacturer should be applied in accordance with references (published 2024-07-16 on Century Systems website). Additionally, it is recommended to immediately disable or restrict access to the Telnet service at the firewall level and replace Telnet with SSH protocol where possible.
Firmware of Century Systems FutureNet NXR-1300, NXR-155/C, NXR-610X, NXR-G050, NXR-G060 devices and other NXR, VXR, and WXR series devices — specific firmware versions indicated in manufacturer references.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HCenturysys Futurenet Nxr 1200
HWCenturysysall versionsCenturysys Futurenet Nxr 1200 Firmware
OSCenturysysall versionsCenturysys Futurenet Nxr 120\/c
HWCenturysysall versionsCenturysys Futurenet Nxr 120\/c Firmware
OSCenturysysall versionsCenturysys Futurenet Nxr 125\/cx Firmware
OSCenturysysall versionsCenturysys Futurenet Nxr 1300 Firmware
OSCenturysys< 7.4.10Centurysys Futurenet Nxr 130\/c
HWCenturysysall versionsCenturysys Futurenet Nxr 130\/c Firmware
OSCenturysysall versionsCenturysys Futurenet Nxr 155\/c Firmware
OSCenturysysall versionsCenturysys Futurenet Nxr 160\/lw
HWCenturysysall versionsCenturysys Futurenet Nxr 160\/lw Firmware
OSCenturysys< 21.8.4Centurysys Futurenet Nxr 230\/c
HWCenturysysall versionsCenturysys Futurenet Nxr 230\/c Firmware
OSCenturysys< 5.30.13Centurysys Futurenet Nxr 350\/c
HWCenturysysall versionsCenturysys Futurenet Nxr 350\/c Firmware
OSCenturysys< 5.30.9cCenturysys Futurenet Nxr 530
HWCenturysysall versionsCenturysys Futurenet Nxr 530 Firmware
OSCenturysys< 21.11.14Centurysys Futurenet Nxr 610x Firmware
OSCenturysys< 21.14.11cCenturysys Futurenet Nxr 650 Firmware
OSCenturysys< 21.16.2Centurysys Futurenet Nxr G050 Firmware
OSCenturysys< 21.12.10Centurysys Futurenet Nxr G060 Firmware
OSCenturysys< 21.15.6Centurysys Futurenet Nxr G100 Firmware
OSCenturysys< 6.23.11Centurysys Futurenet Nxr G110 Firmware
OSCenturysys< 21.7.32Centurysys Futurenet Nxr G120 Firmware
OSCenturysys< 21.15.2cCenturysys Futurenet Nxr G180\/l Ca
HWCenturysysall versionsCenturysys Futurenet Nxr G180\/l Ca Firmware
OSCenturysys< 21.7.28cCenturysys Futurenet Nxr G200 Firmware
OSCenturysys< 9.12.16Centurysys Futurenet Vxr X64
OSCenturysys< 21.7.32Centurysys Futurenet Vxr X86
OSCenturysys< 10.1.5Centurysys Futurenet Wxr 250
HWCenturysysall versions
Related vulnerabilities
Command Injection w urządzeniach FutureNet NXR/VXR/WXR (Century Systems)
FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug ...
Cross-site request forgery (CSRF) vulnerability in multiple Century Systems routers including XR-410 before 1....