Skip to main content

Vendor/product archive

netgear / rax30 CVEs

Beta · best-effort

33 CVEs tagged to netgear / rax304 Critical, 21 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2025-44652

Published Jul 21, 2025

In Netgear RAX30 V1.0.10.94_3, the USERLIMIT_GLOBAL option is set to 0 in multiple bftpd-related configuration files. This can cause DoS attacks when unlimited users are connected.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-44658

Published Jul 21, 2025

In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions. An attacker may exploit th…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-51634

Published Nov 22, 2024

NETGEAR RAX30 Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40480

Published May 3, 2024

NETGEAR RAX30 DHCP Server Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected install…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40479

Published May 3, 2024

NETGEAR RAX30 UPnP Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-35722

Published May 3, 2024

NETGEAR RAX30 UPnP Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34284

Published May 3, 2024

NETGEAR RAX30 Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installa…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34283

Published May 3, 2024

NETGEAR RAX30 USB Share Link Following Information Disclosure Vulnerability. This vulnerability allows physically present attackers to disclose sensitive information on affected i…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27370

Published May 3, 2024

NETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information o…

CVSS 5.7 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-27369

Published May 3, 2024

NETGEAR RAX30 soap_serverd Stack-based Buffer Overflow Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affe…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-27368

Published May 3, 2024

NETGEAR RAX30 soap_serverd Stack-based Buffer Overflow Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affec…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-27367

Published May 3, 2024

NETGEAR RAX30 libcms_cli Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installa…

CVSS 8.0 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-27357

Published May 3, 2024

NETGEAR RAX30 GetInfo Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affect…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-28338

Published Mar 15, 2023

Any request send to a Netgear Nighthawk Wifi6 Router (RAX30)'s web service containing a “Content-Type” of “multipartboundary=” will result in the request body being written to “/t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28337

Published Mar 15, 2023

When uploading a firmware image to a Netgear Nighthawk Wifi6 Router (RAX30), a hidden “forceFWUpdate” parameter may be provided to force the upgrade to complete and bypass certain…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 33 CVEsPage 1 of 2