📦 Rax30 Firmware

by Netgear

🔍 What is Rax30 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-44658

CRITICAL CVSS 9.8 Jul 21, 2025

This vulnerability allows attackers to upload malicious scripts with non-.php extensions that the Netgear RAX30 router's PHP-FPM configuration incorrectly executes as PHP code. This bypasses standard ...

CVE-2023-1327

CRITICAL CVSS 9.8 Mar 14, 2023

CVE-2023-1327 is an authentication bypass vulnerability in Netgear RAX30 routers that allows unauthenticated attackers to reset the admin password and gain full administrative access to the web manage...

CVE-2025-12943

HIGH CVSS 7.5 Nov 11, 2025

This vulnerability allows attackers who can intercept and modify traffic destined for affected NETGEAR routers to execute arbitrary commands on the device. It affects NETGEAR RAX30 and RAXE300 routers...

CVE-2023-51635

HIGH CVSS 8.8 Nov 22, 2024

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on NETGEAR RAX30 routers without authentication. The flaw exists in the fing_dil service due to improper length v...

CVE-2023-40479

HIGH CVSS 8.8 May 3, 2024

This vulnerability allows attackers on the same local network to execute arbitrary commands with root privileges on NETGEAR RAX30 routers without authentication. The flaw exists in the UPnP service du...

CVE-2023-34285

HIGH CVSS 8.8 May 3, 2024

This is a critical stack-based buffer overflow vulnerability in NETGEAR RAX30 routers that allows network-adjacent attackers to execute arbitrary code as root without authentication. The flaw exists i...

CVE-2023-27368

HIGH CVSS 8.8 May 3, 2024

This vulnerability allows network-adjacent attackers to execute arbitrary code on NETGEAR RAX30 routers without authentication. Attackers can exploit a stack-based buffer overflow in the soap_serverd ...

CVE-2023-27360

HIGH CVSS 8.8 May 3, 2024

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on NETGEAR RAX30 routers without authentication, due to a misconfiguration in the lighttpd HTTP server that permi...

CVE-2023-27358

HIGH CVSS 8.8 May 3, 2024

This vulnerability allows network-adjacent attackers to execute SQL injection via unauthenticated SOAP requests on NETGEAR RAX30 routers, potentially leading to remote code execution. Attackers can ex...

CVE-2023-48725

HIGH CVSS 7.2 Mar 7, 2024

This CVE describes a stack-based buffer overflow vulnerability in Netgear RAX30 routers' JSON parsing functionality. An authenticated attacker can send a specially crafted HTTP request to execute arbi...

CVE-2023-28337

HIGH CVSS 8.8 Mar 15, 2023

This vulnerability allows attackers to upload malicious firmware to Netgear Nighthawk RAX30 routers by exploiting a hidden 'forceFWUpdate' parameter that bypasses validation checks. This affects all u...

CVE-2023-40478

MEDIUM CVSS 6.8 May 3, 2024

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on NETGEAR RAX30 routers by exploiting a stack-based buffer overflow in the telnet CLI service. Although authenti...

CVE-2023-34283

MEDIUM CVSS 4.6 May 3, 2024

This vulnerability allows physically present attackers to access arbitrary files on NETGEAR RAX30 routers by exploiting improper symbolic link handling on USB media. Attackers can read sensitive syste...

CVE-2023-27370

MEDIUM CVSS 5.7 May 3, 2024

This vulnerability allows network-adjacent attackers to bypass authentication and access plaintext configuration secrets stored on NETGEAR RAX30 routers. Attackers can steal stored credentials like ad...

CVE-2023-27357

MEDIUM CVSS 6.5 May 3, 2024

This vulnerability allows network-adjacent attackers to access sensitive information from NETGEAR RAX30 routers without authentication. The flaw exists in SOAP request handling where authentication ch...