{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-01T19:20:09.716","vulnerabilities":[{"cve":{"id":"CVE-2024-50357","sourceIdentifier":"vultures@jpcert.or.jp","published":"2024-11-29T10:15:10.833","lastModified":"2026-04-15T00:35:42.020","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in the initial (factory default) configuration. But, REST-APIs are unexpectedly enabled when the affected product is powered up, provided either http-server (GUI) or Web authentication is enabled. The factory default configuration makes http-server (GUI) enabled, which means REST-APIs are also enabled. The username and the password for REST-APIs are configured in the factory default configuration. As a result, an attacker may obtain and/or alter the affected product's settings via REST-APIs."},{"lang":"es","value":"Los enrutadores de la serie FutureNet NXR proporcionados por Century Systems Co., Ltd. tienen API REST, que están configuradas como deshabilitadas en la configuración inicial (predeterminada de fábrica). Sin embargo, las API REST se habilitan inesperadamente cuando se enciende el producto afectado, siempre que esté habilitada la autenticación web o del servidor http (GUI). La configuración predeterminada de fábrica habilita el servidor http (GUI), lo que significa que las API REST también están habilitadas. El nombre de usuario y la contraseña para las API REST están configurados en la configuración predeterminada de fábrica. Como resultado, un atacante puede obtener y/o alterar la configuración del producto afectado a través de las API REST."}],"metrics":{"cvssMetricV30":[{"source":"vultures@jpcert.or.jp","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"vultures@jpcert.or.jp","type":"Secondary","description":[{"lang":"en","value":"CWE-684"}]}],"references":[{"url":"https://jvn.jp/en/vu/JVNVU95001899/","source":"vultures@jpcert.or.jp"},{"url":"https://www.centurysys.co.jp/backnumber/nxr_common/20241031-01.html","source":"vultures@jpcert.or.jp"}]}}]}