Description
Authentication bypass vulnerability exists in FutureNet AS series (Industrial Routers) provided by Century Systems Co., Ltd. If this vulnerability is exploited, a remote unauthenticated attacker may obtain the device information such as MAC address by sending a specially crafted request.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected products
- Century Systems Co., Ltd. / FutureNet AS-210/U4firmware Version 2.6.4 and earlier – firmware Version 2.6.4 and earlier
- Century Systems Co., Ltd. / FutureNet AS-250/F-KOfirmware Version 1.14.0 and earlier – firmware Version 1.14.0 and earlier
- Century Systems Co., Ltd. / FutureNet AS-250/F-SCfirmware Version 1.14.0 and earlier – firmware Version 1.14.0 and earlier
- Century Systems Co., Ltd. / FutureNet AS-250/KLfirmware Version 1.14.0 and earlier – firmware Version 1.14.0 and earlier
- Century Systems Co., Ltd. / FutureNet AS-250/KL Rev2firmware Version 2.6.4 and earlier – firmware Version 2.6.4 and earlier
- Century Systems Co., Ltd. / FutureNet AS-250/Lfirmware Version 2.6.4 and earlier – firmware Version 2.6.4 and earlier
- Century Systems Co., Ltd. / FutureNet AS-250/NLfirmware Version 1.14.0 and earlier – firmware Version 1.14.0 and earlier
- Century Systems Co., Ltd. / FutureNet AS-250/Sfirmware Version 1.14.0 and earlier – firmware Version 1.14.0 and earlier
- Century Systems Co., Ltd. / FutureNet AS-M250/KLfirmware Version 2.6.4 and earlier – firmware Version 2.6.4 and earlier
- Century Systems Co., Ltd. / FutureNet AS-M250/Lfirmware Version 2.6.4 and earlier – firmware Version 2.6.4 and earlier
- Century Systems Co., Ltd. / FutureNet AS-M250/NLfirmware Version 2.6.4 and earlier – firmware Version 2.6.4 and earlier
- Century Systems Co., Ltd. / FutureNet AS-P250/KLfirmware Version 2.6.4 and earlier – firmware Version 2.6.4 and earlier
- Century Systems Co., Ltd. / FutureNet AS-P250/NLfirmware Version 2.6.4 and earlier – firmware Version 2.6.4 and earlier