Furunosystems develops a product line of network appliances and switches—such as the Acera routing and access-control series—that serve small-to-medium enterprise connectivity and security functions. The observed vulnerabilities cluster around authentication and web-interface handling weaknesses including authentication bypass, improper credential validation, cross-site request forgery, path traversal, and cross-site scripting, reflecting the complexity of embedded web management interfaces and access-control logic in network devices. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Furunosystems over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-42771HIGH Authentication bypass vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adjacent unauthenticated attacker w | Oct 3, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-41086HIGH Cross-site request forgery (CSRF) vulnerability exists in FURUNO SYSTEMS wireless LAN access point devices. If a user views a malicious page while logged in, unintended operations | Oct 3, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-39222HIGH OS command injection vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to execute an arbitrary OS command that is not intended to be ex | Oct 3, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-39429MEDIUM Cross-site scripting vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to inject an arbitrary script via a crafted configuration. Affec | Oct 3, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-43627MEDIUM Path traversal vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adjacent authenticated attacker to alter c | Oct 3, 2023 | 5.7 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Furunosystems.
Media articles that mention a CVE ID that affects a product developed by Furunosystems — matched by CVE ID, not by vendor name.