FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allow an administrative user to execute an arbitrary OS command, obtain and/or alter sensitive information, and cause a denial-of-service (DoS) condition.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
https://www.centurysys.co.jp/backnumber/nxr_common/20240716-01.html | vendor advisory |
https://www.centurysys.co.jp/backnumber/nxr_common/20240716-03.html | vendor advisory |
https://jvn.jp/en/vu/JVNVU96424864/ | third party advisory |