CVE-2025-30485 Details
Description
UNIX symbolic link (Symlink) following issue exists in FutureNet NXR series, VXR series and WXR series routers. Attaching to the affected product an external storage containing malicious symbolic link files, a logged-in administrative user may obtain and/or destroy internal files.
A vulnerability exists in FutureNet NXR series, VXR series, and WXR series routers, all provided by Century Systems Co., Ltd. These routers improperly handle symbolic link files. When an external storage device containing malicious symbolic link files is connected to the router, a logged-in administrative user could access or delete internal files. This issue has been assigned the identifier CVE-2025-30485.
Users are advised to update the router's firmware to the latest version. For NXR and VXR series, instructions for updating the firmware are available on the Century Systems website. Some affected products are no longer supported and users are recommended to switch to alternatives.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 3, 2025CISA-ADP
Assessed Apr 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/vu/JVNVU92821536/ | [email protected] | AdvisoryRemedy |
| https://www.centurysys.co.jp/backnumber/common/jvnvu92821536.html | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-61 | UNIX Symbolic Link (Symlink) Following | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Century Systems FutureNet NXR-1420 | All versions |
CPE
Remediation
| |
| Century Systems FutureNet NXR-1300 | <= 7.4.12 (semver) |
CPE
Remediation
| |
| Century Systems FutureNet NXR-650 | <= 21.16.5 (semver) |
CPE
Remediation
| |
| Century Systems FutureNet NXR-610X | <= 21.14.11D |
CPE
Remediation
| |
| Century Systems FutureNet NXR-530 | <= 21.11.15 (semver) |
CPE
Remediation
| |
| Century Systems FutureNet NXR-350 | <= 5.30.9C |
CPE
Remediation
| |
| Century Systems FutureNet NXR-230 | <= 5.30.13 (semver) |
CPE
Remediation
| |
| Century Systems FutureNet NXR-160 | <= 21.8.4 (semver) |
CPE
Remediation
| |
| Century Systems FutureNet NXR-G540 | All versions |
CPE
Remediation
| |
| Century Systems FutureNet NXR-G260 | All versions |
CPE
Remediation
| |
| Century Systems FutureNet NXR-G240 | All versions |
CPE
Remediation
| |
| Century Systems FutureNet NXR-G180 | All versions |
CPE
Remediation
| |
| Century Systems FutureNet NXR-G120 | All versions |
CPE
Remediation
| |
| Century Systems FutureNet NXR-G110 | All versions |
CPE
Remediation
| |
| Century Systems FutureNet NXR-G100 | All versions |
CPE
Remediation
| |
| Century Systems FutureNet NXR-G060 | All versions |
CPE
Remediation
| |
| Century Systems FutureNet NXR-G050 | All versions |
CPE
Remediation
| |
| Century Systems FutureNet VXR-x64 | <= 21.7.33 (semver) |
CPE
Remediation
| |
| Century Systems FutureNet VXR-x86 | <= 10.1.5 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 3, 2025 | New CVE Received | [email protected] |
Volerion