# Century Systems FutureNet routers face RCE flaws

Published: 2024-07-31 · Severity: medium · Sectors: infrastructure, telecommunications
Canonical: https://vorant.io/reports/1979644a-1bdf-5801-8db8-fdfea19698d2/century-systems-futurenet-routers-face-rce-flaws

> IPA warns of vulnerabilities in Century Systems' FutureNet NXR, VXR, and WXR VPN routers that could allow unrestricted Telnet access, arbitrary OS command execution, and data theft.

IPA (Information-technology Promotion Agency, Japan) issued an alert regarding multiple vulnerabilities in Century Systems' FutureNet NXR and WXR series VPN routers and the VXR series virtual software router. If exploited, these flaws could allow unrestricted access via Telnet, execution of arbitrary OS commands, and theft of sensitive information from affected devices.

The advisory notes these devices are often deployed as VPN endpoints replacing legacy ISDN lines, and are frequently unmanaged as IT assets, increasing the risk that vulnerable units remain unpatched and exposed to the internet. IPA warns that successful exploitation could lead not only to compromise of the owning organization's network but also to the device being repurposed as an Operational Relay Box (ORB), unwittingly facilitating attacks against third-party organizations — a pattern previously observed with other vendors' IoT routers.

IPA recommends organizations verify whether they use the affected FutureNet product lines, apply firmware updates provided by Century Systems, and consider using services like SHODAN to identify exposed IoT/router assets. Some affected product lines have reached end-of-support status, and the vendor recommends discontinuing use or migrating to successor products for those devices.

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/alert20240801.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1979644a-1bdf-5801-8db8-fdfea19698d2/century-systems-futurenet-routers-face-rce-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
