CVE-2024-50357 Information
Dec 01, 2024
cve
Description
FutureNet NXR series routers provided by Century Systems Co. Ltd. have REST-APIs which are configured as disabled in the initial (factory default) configuration. But REST-APIs are unexpectedly enabled when the affected product is powered up provided either http-server (GUI) or Web authentication is enabled. The factory default configuration makes http-server (GUI) enabled which means REST-APIs are also enabled. The username and the password for REST-APIs are configured in the factory default configuration. As a result an attacker may obtain and/or alter the affected product’s settings via REST-APIs.
Reference
https://jvn.jp/en/vu/JVNVU95001899/ https://www.centurysys.co.jp/backnumber/nxr_common/20241031-01.html
Share on: