PT-2024-5243 · Futurenet · Futurenet Nxr Series

Published

2024-06-06

·

Updated

2025-04-01

·

CVE-2024-36491

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: FutureNet NXR series versions (affected versions not specified) FutureNet VXR series versions (affected versions not specified) FutureNet WXR series versions (affected versions not specified)
Description: The issue is related to the lack of measures to neutralize special elements used in the operating system command. This can allow a remote attacker to gain unauthorized access to protected information, execute arbitrary commands, or cause a denial of service condition. A remote unauthenticated attacker can execute an arbitrary OS command, obtain and/or alter sensitive information, and cause a denial of service (DoS) condition.
Recommendations: For FutureNet NXR series, update to a version that includes security patches for this issue. For FutureNet VXR series, update to a version that includes security patches for this issue. For FutureNet WXR series, update to a version that includes security patches for this issue. As a temporary workaround, consider restricting access to the operating system command to minimize the risk of exploitation.

Fix

DoS

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-05855
CVE-2024-36491

Affected Products

Futurenet Nxr Series