Century Systems FutureNet MA and IP-K Series OS Command Injection Vulnerability

Vulnerability

An OS command injection vulnerability has been identified in the FutureNet MA and IP-K series products by Century Systems Co., Ltd. This vulnerability allows a user logged into the Web UI to execute arbitrary OS commands. The issue affects multiple versions across different FutureNet MA series and the IP-K series.

Impact

Exploitation of this vulnerability allows authenticated users to execute arbitrary OS commands on the affected device.

Remediation

Users are advised to update the firmware to the latest version. Instructions for updating the firmware are available on the Century Systems website. If an immediate update is not possible, it is recommended to strengthen access controls by allowing communication only from trusted IP addresses and to disable the Web server function on MA series devices.

Added: Oct 31, 2025, 6:18 AM
Updated: Oct 31, 2025, 6:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.2
remediation
0.0
relevance
0.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.