CVE-2025-30485

MEDIUM

FutureNet NXR/WXR/VXR - Info Disclosure

Title source: llm
STIX 2.1

Description

UNIX symbolic link (Symlink) following issue exists in FutureNet NXR series, VXR series and WXR series routers. Attaching to the affected product an external storage containing malicious symbolic link files, a logged-in administrative user may obtain and/or destroy internal files.

Scores

CVSS v3 6.2
EPSS 0.0019
EPSS Percentile 40.6%
Attack Vector PHYSICAL
CVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-61
Status published
Products (32)
Century Systems Co., Ltd./FutureNet NXR-120/C
Century Systems Co., Ltd./FutureNet NXR-1200
Century Systems Co., Ltd./FutureNet NXR-125/CX
Century Systems Co., Ltd./FutureNet NXR-130/C
Century Systems Co., Ltd./FutureNet NXR-1300 series firmware version 7.4.12 and earlier
Century Systems Co., Ltd./FutureNet NXR-1420 firmware version 31.0.1 and earlier
Century Systems Co., Ltd./FutureNet NXR-155/C-L
Century Systems Co., Ltd./FutureNet NXR-155/C-WM
Century Systems Co., Ltd./FutureNet NXR-155/C-XW
Century Systems Co., Ltd./FutureNet NXR-160/LW firmware version 21.8.4 and earlier
... and 22 more
Published Apr 03, 2025
Tracked Since Feb 18, 2026