First published: Mon Mar 03 2025(Updated: )
Authentication bypass vulnerability exists in FutureNet AS series (Industrial Routers) provided by Century Systems Co., Ltd. If this vulnerability is exploited, a remote unauthenticated attacker may obtain the device information such as MAC address by sending a specially crafted request.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Century Systems FutureNet AS series |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24846 is classified as a high severity vulnerability due to the potential for remote unauthenticated access to device information.
To fix CVE-2025-24846, update the firmware of the FutureNet AS series routers to the latest version provided by Century Systems.
Exploiting CVE-2025-24846 could allow an attacker to retrieve sensitive device information such as MAC addresses without authentication.
CVE-2025-24846 affects users of the FutureNet AS series industrial routers manufactured by Century Systems Co., Ltd.
Currently, there are no known workarounds for CVE-2025-24846, making it essential to apply the recommended firmware update.