Vulnerabilities
Summary — last 7 days
New vulnerabilities2,624▼ 224 vs. last week
Critical / high1,373▲ 143 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)81▼ 449 vs. last week
9 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (6.9) | 0.32% | — | Century Systems Futurenet MAAICentury Systems Ip-k SeriesAI | 10/31/2025 | 6/17/2026 | FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection information on the internal web page. With some crafted HTTP request, they can be accessed without authentication. | |
| Deferred | High (8.6) | 1.2% | — | Century Systems Futurenet MAAICentury Systems Ip-k SeriesAI | 10/31/2025 | 6/17/2026 | FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user who logs in to the Web UI of the product may execute an arbitrary OS command. | |
| Deferred | Medium (6.2) | 0.32% | — | Futurenet NXRAIFuturenet VXRAIFuturenet WXRAI | 4/3/2025 | 6/17/2026 | UNIX symbolic link (Symlink) following issue exists in FutureNet NXR series, VXR series and WXR series routers. Attaching to the affected product an external storage containing malicious symbolic link files, a logged-in administrative user may obtain and/or destroy internal files. | |
| Deferred | Medium (5.3) | 0.51% | — | Century Systems Futurenet ASAICentury Systems FAAI | 3/3/2025 | 6/17/2026 | Buffer overflow vulnerability exists in FutureNet AS series (Industrial Routers) and FA series (Protocol Conversion Machine) provided by Century Systems Co., Ltd. If this vulnerability is exploited, a remote unauthenticated attacker may reboot the device by sending a specially crafted request. | |
| Deferred | High (7.5) | 0.53% | — | Century Systems Futurenet ASAI | 3/3/2025 | 6/17/2026 | Authentication bypass vulnerability exists in FutureNet AS series (Industrial Routers) provided by Century Systems Co., Ltd. If this vulnerability is exploited, a remote unauthenticated attacker may obtain the device information such as MAC address by sending a specially crafted request. | |
| Deferred | Critical (9.8) | 0.55% | — | Century Systems Futurenet NXRAI | 11/29/2024 | 6/17/2026 | FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in the initial (factory default) configuration. But, REST-APIs are unexpectedly enabled when the affected product is powered up, provided either http-server (GUI) or Web authentication is enabled. The… | |
| Modified | Critical (9.8) | 0.65% | — | Centurysys Futurenet Nxr-1300 FirmwareCenturysys Futurenet Nxr-155/c FirmwareCenturysys Futurenet Nxr-610x FirmwareCenturysys Futurenet Nxr-g050 Firmware+18 | 7/17/2024 | 6/17/2026 | FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allow an administrative user to execute an arbitrary OS command, obtain and/or alter sensitive information, and cause a denial-of-service (DoS) condition. | |
| Modified | High (8.8) | 0.62% | — | Centurysys Futurenet Nxr-1300 FirmwareCenturysys Futurenet Nxr-155/c FirmwareCenturysys Futurenet Nxr-610x FirmwareCenturysys Futurenet Nxr-g050 Firmware+18 | 7/17/2024 | 6/17/2026 | FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug code vulnerability. If a user who knows how to use the debug function logs in to the product, the debug function may be used and an arbitrary OS command may be executed. | |
| Modified | Critical (9.1) | 0.75% | — | Centurysys Futurenet Nxr-1300 FirmwareCenturysys Futurenet Nxr-155/c FirmwareCenturysys Futurenet Nxr-610x FirmwareCenturysys Futurenet Nxr-g050 Firmware+18 | 7/17/2024 | 6/17/2026 | Initialization of a resource with an insecure default vulnerability in FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allows a remote unauthenticated attacker to access telnet service unlimitedly. |