Century Systems FutureNet AS-250/NL
- <= 1.14.0
An authentication bypass vulnerability has been identified in the FutureNet AS series industrial routers, specifically in versions through 1.14.0 and in certain 2.6.4 and 2.6.6 releases. This vulnerability allows remote, unauthenticated attackers to access device information, such as the MAC address, by sending specially crafted requests.
Exploitation of this vulnerability allows remote, unauthenticated attackers to bypass authentication and access sensitive device information, including the MAC address.
Users are advised to update the firmware to the latest version. For AS series routers, the updated version is 3.1.1. For FA series devices, the latest version is 1.0.2 for the FA-215 model and 1.1.10 for the FA-210 model. Instructions for updating the firmware are available on the Century Systems website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.