FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug code vulnerability. If a user who knows how to use the debug function logs in to the product, the debug function may be used and an arbitrary OS command may be executed.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
The product is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information.
Link | Tags |
---|---|
https://www.centurysys.co.jp/backnumber/nxr_common/20240716-01.html | vendor advisory |
https://www.centurysys.co.jp/backnumber/nxr_common/20240716-03.html | vendor advisory |
https://jvn.jp/en/vu/JVNVU96424864/ | third party advisory |