FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection information on the internal web page. With some crafted HTTP request, they can be accessed without authentication.
History

Mon, 03 Nov 2025 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Centurysys
Centurysys futurenet Ip-k Series
Centurysys futurenet Ma-e300 Series
Centurysys futurenet Ma-p Series
Centurysys futurenet Ma-s Series
Centurysys futurenet Ma-x Series
Vendors & Products Centurysys
Centurysys futurenet Ip-k Series
Centurysys futurenet Ma-e300 Series
Centurysys futurenet Ma-p Series
Centurysys futurenet Ma-s Series
Centurysys futurenet Ma-x Series

Fri, 31 Oct 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Oct 2025 06:00:00 +0000

Type Values Removed Values Added
Description FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection information on the internal web page. With some crafted HTTP request, they can be accessed without authentication.
Weaknesses CWE-552
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2025-10-31T05:55:02.996Z

Updated: 2025-10-31T17:07:56.496Z

Reserved: 2025-10-17T08:08:12.702Z

Link: CVE-2025-58152

cve-icon Vulnrichment

Updated: 2025-10-31T17:07:33.107Z

cve-icon NVD

Status : Received

Published: 2025-10-31T06:15:34.150

Modified: 2025-10-31T06:15:34.150

Link: CVE-2025-58152

cve-icon Redhat

No data.