CVE-2024-50357
FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in the initial (factory default) configuration. But, REST-APIs are unexpectedly enabled when the affected product is powered up, provided either http-server (GUI) or Web authentication is enabled. The factory default configuration makes http-server (GUI) enabled, which means REST-APIs are also enabled. The username and the password for REST-APIs are configured in the factory default configuration. As a result, an attacker may obtain and/or alter the affected product's settings via REST-APIs.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.55%
- Percentil entre todas las CVEs puntuadas: 44
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access95 % - Impacto principal
T1005Data from Local Systemcollection85 % - Impacto secundario
T1078.001Default Accountsstealth · persistence · privilege escalation · initial access75 % - Impacto secundario
T1565.001Stored Data Manipulationimpact80 %
Router accesible en red con REST-APIs habilitadas de fábrica y credenciales por defecto; permite leer configuración (T1005), modificarla (T1565.001) y reutilizar credenciales expuestas (T1078.001).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-684
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-50357",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-50357",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-11-29T13:27:09.092320Z"
}
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "vultures@jpcert.or.jp",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "vultures@jpcert.or.jp",
"affectedData": [
{
"vendor": "Century Systems Co., Ltd.",
"product": "FutureNet NXR-G110 series",
"versions": [
{
"status": "affected",
"version": "firmware versions 21.15.7 and later but prior to 21.15.9"
}
]
},
{
"vendor": "Century Systems Co., Ltd.",
"product": "FutureNet NXR-G060 series",
"versions": [
{
"status": "affected",
"version": "firmware versions prior to 21.15.6C1"
}
]
},
{
"vendor": "Century Systems Co., Ltd.",
"product": "FutureNet NXR-G050 series",
"versions": [
{
"status": "affected",
"version": "firmware versions 21.12.5 and later but prior to 21.12.11"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:o:centurysys:futurenet_nxr-g110_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "centurysys",
"product": "futurenet_nxr-g110_firmware",
"versions": [
{
"status": "affected",
"version": "21.15.7",
"lessThan": "21.15.9",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:centurysys:futurenet_nxr-g060_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "centurysys",
"product": "futurenet_nxr-g060_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "21.15.6C1",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:centurysys:futurenet_nxr-g050_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "centurysys",
"product": "futurenet_nxr-g050_firmware",
"versions": [
{
"status": "affected",
"version": "21.12.5",
"lessThan": "21.12.11",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-11-29T10:15:10.833",
"references": [
{
"url": "https://jvn.jp/en/vu/JVNVU95001899/",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://www.centurysys.co.jp/backnumber/nxr_common/20241031-01.html",
"source": "vultures@jpcert.or.jp"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "vultures@jpcert.or.jp",
"description": [
{
"lang": "en",
"value": "CWE-684"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in the initial (factory default) configuration. But, REST-APIs are unexpectedly enabled when the affected product is powered up, provided either http-server (GUI) or Web authentication is enabled. The factory default configuration makes http-server (GUI) enabled, which means REST-APIs are also enabled. The username and the password for REST-APIs are configured in the factory default configuration. As a result, an attacker may obtain and/or alter the affected product's settings via REST-APIs."
},
{
"lang": "es",
"value": "Los enrutadores de la serie FutureNet NXR proporcionados por Century Systems Co., Ltd. tienen API REST, que están configuradas como deshabilitadas en la configuración inicial (predeterminada de fábrica). Sin embargo, las API REST se habilitan inesperadamente cuando se enciende el producto afectado, siempre que esté habilitada la autenticación web o del servidor http (GUI). La configuración predeterminada de fábrica habilita el servidor http (GUI), lo que significa que las API REST también están habilitadas. El nombre de usuario y la contraseña para las API REST están configurados en la configuración predeterminada de fábrica. Como resultado, un atacante puede obtener y/o alterar la configuración del producto afectado a través de las API REST."
}
],
"lastModified": "2026-06-17T08:04:17.943",
"sourceIdentifier": "vultures@jpcert.or.jp"
}