Vulnerabilities > Centurysys

DATE CVE VULNERABILITY TITLE RISK
2024-07-17 CVE-2024-31070 Insecure Default Initialization of Resource vulnerability in Centurysys products
Initialization of a resource with an insecure default vulnerability in FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd.
network
low complexity
centurysys CWE-1188
critical
9.1
2024-07-17 CVE-2024-36475 OS Command Injection vulnerability in Centurysys products
FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd.
network
low complexity
centurysys CWE-78
8.8
2024-07-17 CVE-2024-36491 OS Command Injection vulnerability in Centurysys products
FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd.
network
low complexity
centurysys CWE-78
critical
9.8
2009-03-09 CVE-2008-6449 Cross-Site Request Forgery (CSRF) vulnerability in Centurysys products
Cross-site request forgery (CSRF) vulnerability in multiple Century Systems routers including XR-410 before 1.6.9, XR-510 before 3.5.3, XR-440 before 1.7.8, and other XR series routers from XR-510 to XR-730 allows remote attackers to modify configuration as the administrator via unknown vectors.
network
high complexity
centurysys CWE-352
4.0