VYPR

Rax30 Firmware

by Netgear

CVEs (29)

  • CVE-2023-27853CriMar 10, 2023
    risk 0.65cvss 9.8epss 0.20

    NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a format string vulnerability in a SOAP service that could allow an attacker to execute arbitrary code on the device.

  • CVE-2025-44658CriJul 21, 2025
    risk 0.64cvss 9.8epss 0.01

    In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions. An attacker may exploit this by uploading malicious scripts disguised with alternate extensions and tricking the web server…

  • CVE-2023-1327CriMar 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Netgear RAX30 (AX2400), prior to version 1.0.6.74, was affected by an authentication bypass vulnerability, allowing an unauthenticated attacker to gain administrative access to the device's web management interface by resetting the admin password.

  • CVE-2023-27852CriMar 10, 2023
    risk 0.64cvss 9.8epss 0.01

    NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a buffer overflow vulnerability in various CGI mechanisms that could allow an attacker to execute arbitrary code on the device.

  • CVE-2023-51635HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.01

    NETGEAR RAX30 fing_dil Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this…

  • CVE-2023-40480HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    NETGEAR RAX30 DHCP Server Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The…

  • CVE-2023-40479HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    NETGEAR RAX30 UPnP Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The…

  • CVE-2023-35722HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    NETGEAR RAX30 UPnP Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The…

  • CVE-2023-34285HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    NETGEAR RAX30 cmsCli_authenticate Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this…

  • CVE-2023-27369HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    NETGEAR RAX30 soap_serverd Stack-based Buffer Overflow Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30. Authentication is not required to exploit this vulnerability. …

  • CVE-2023-27368HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    NETGEAR RAX30 soap_serverd Stack-based Buffer Overflow Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this…

  • CVE-2023-28337HigMar 15, 2023
    risk 0.57cvss 8.8epss 0.01

    When uploading a firmware image to a Netgear Nighthawk Wifi6 Router (RAX30), a hidden “forceFWUpdate” parameter may be provided to force the upgrade to complete and bypass certain validation checks. End users can use this to upload modified, unofficial, and potentially…

  • CVE-2023-27851HigMar 10, 2023
    risk 0.57cvss 8.8epss 0.01

    NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that unintentionally allows users with upload permissions to execute arbitrary code on the device.

  • CVE-2023-1205HigMar 10, 2023
    risk 0.57cvss 8.8epss 0.00

    NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 is vulnerable to cross-site request forgery attacks on all endpoints due to improperly implemented CSRF protections.

  • CVE-2022-47209HigDec 16, 2022
    risk 0.57cvss 8.8epss 0.00

    A support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “support” and cannot be changed by a user via any normally accessible means.

  • CVE-2023-27367HigMay 3, 2024
    risk 0.52cvss 8.0epss 0.01

    NETGEAR RAX30 libcms_cli Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit this vulnerability,…

  • CVE-2023-27361HigMay 3, 2024
    risk 0.52cvss 8.0epss 0.01

    NETGEAR RAX30 rex_cgi JSON Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is required to exploit this…

  • CVE-2023-27356HigMay 3, 2024
    risk 0.52cvss 8.0epss 0.01

    NETGEAR RAX30 logCtrl Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit this vulnerability, the…

  • CVE-2022-47210HigDec 16, 2022
    risk 0.51cvss 7.8epss 0.00

    The default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, however, appear to be fed directly into a system call or other similar function. This allows any authenticated user to execute arbitrary…

  • CVE-2025-12943HigNov 11, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper certificate validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router) and RAXE300 (Nighthawk AXE7800 Tri-Band WiFi 6E Router) allows attackers with the ability to intercept and tamper traffic destined to the device to execute…

Page 1 of 2