Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2025-24846", "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce", "state": "PUBLISHED", "assignerShortName": "jpcert", "dateReserved": "2025-02-17T04:46:48.959Z", "datePublished": "2025-03-03T08:23:52.407Z", "dateUpdated": "2025-03-03T13:17:41.955Z"}, "containers": {"cna": {"affected": [{"vendor": "Century Systems Co., Ltd.", "product": "FutureNet AS-250/S", "versions": [{"version": "firmware Version 1.14.0 and earlier", "status": "affected"}]}, {"vendor": "Century Systems Co., Ltd.", "product": "FutureNet AS-250/F-SC", "versions": [{"version": "firmware Version 1.14.0 and earlier", "status": "affected"}]}, {"vendor": "Century Systems Co., Ltd.", "product": "FutureNet AS-250/F-KO", "versions": [{"version": "firmware Version 1.14.0 and earlier", "status": "affected"}]}, {"vendor": "Century Systems Co., Ltd.", "product": "FutureNet AS-250/NL", "versions": [{"version": "firmware Version 1.14.0 and earlier", "status": "affected"}]}, {"vendor": "Century Systems Co., Ltd.", "product": "FutureNet AS-250/KL", "versions": [{"version": "firmware Version 1.14.0 and earlier", "status": "affected"}]}, {"vendor": "Century Systems Co., Ltd.", "product": "FutureNet AS-250/KL Rev2", "versions": [{"version": "firmware Version 2.6.4 and earlier", "status": "affected"}]}, {"vendor": "Century Systems Co., Ltd.", "product": "FutureNet AS-250/L", "versions": [{"version": "firmware Version 2.6.4 and earlier", "status": "affected"}]}, {"vendor": "Century Systems Co., Ltd.", "product": "FutureNet AS-M250/L", "versions": [{"version": "firmware Version 2.6.4 and earlier", "status": "affected"}]}, {"vendor": "Century Systems Co., Ltd.", "product": "FutureNet AS-M250/KL", "versions": [{"version": "firmware Version 2.6.4 and earlier", "status": "affected"}]}, {"vendor": "Century Systems Co., Ltd.", "product": "FutureNet AS-M250/NL", "versions": [{"version": "firmware Version 2.6.4 and earlier", "status": "affected"}]}, {"vendor": "Century Systems Co., Ltd.", "product": "FutureNet AS-P250/NL", "versions": [{"version": "firmware Version 2.6.4 and earlier", "status": "affected"}]}, {"vendor": "Century Systems Co., Ltd.", "product": "FutureNet AS-P250/KL", "versions": [{"version": "firmware Version 2.6.4 and earlier", "status": "affected"}]}, {"vendor": "Century Systems Co., Ltd.", "product": "FutureNet AS-210/U4", "versions": [{"version": "firmware Version 2.6.4 and earlier", "status": "affected"}]}], "descriptions": [{"lang": "en", "value": "Authentication bypass vulnerability exists in FutureNet AS series (Industrial Routers) provided by Century Systems Co., Ltd. If this vulnerability is exploited, a remote unauthenticated attacker may obtain the device information such as MAC address by sending a specially crafted request."}], "problemTypes": [{"descriptions": [{"description": "Authentication Bypass Using an Alternate Path or Channel", "lang": "en-US", "cweId": "CWE-288", "type": "CWE"}]}], "references": [{"url": "https://www.centurysys.co.jp/backnumber/common/jvnvu96398949.html"}, {"url": "https://jvn.jp/en/vu/JVNVU96398949/"}], "metrics": [{"format": "CVSS", "scenarios": [{"lang": "en-US", "value": "GENERAL"}], "cvssV3_1": {"version": "3.1", "baseSeverity": "HIGH", "baseScore": 7.5, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}}], "providerMetadata": {"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce", "shortName": "jpcert", "dateUpdated": "2025-03-03T08:23:52.407Z"}}, "adp": [{"metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2025-03-03T13:15:19.774363Z", "id": "CVE-2025-24846", "options": [{"Exploitation": "none"}, {"Automatable": "yes"}, {"Technical Impact": "partial"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2025-03-03T13:17:41.955Z"}}]}}