Critical severity9.8NVD Advisory· Published Jul 21, 2025· Updated Jun 17, 2026
CVE-2025-44658
CVE-2025-44658
Description
In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions. An attacker may exploit this by uploading malicious scripts disguised with alternate extensions and tricking the web server into executing them as PHP, bypassing security mechanisms based on file extension filtering. This may lead to remote code execution (RCE), information disclosure, or full system compromise.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:netgear:rax30_firmware:1.0.10.94:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- www.netgear.com/about/security/nvdVendor Advisory
- www.notion.so/CVE-2025-44658-24754a1113e780df8f72c779a108f75bnvdThird Party Advisory
- gist.github.com/TPCchecker/c72eea7a3f89070dab7dfdbf7504b2d6nvdBroken Link
News mentions
0No linked articles in our index yet.