Netgear Rax30 Firmware vulnerabilities
30 known vulnerabilities affecting netgear/rax30_firmware.
Total CVEs
30
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH19MEDIUM7
Vulnerabilities
Page 2 of 2
CVE-2023-27370MEDIUMCVSS 5.7fixed in 1.0.10.942024-05-03
CVE-2023-27370 [MEDIUM] CWE-312 CVE-2023-27370: NETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure Vulnerability. This vuln
NETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
nvd
CVE-2023-48725HIGHCVSS 8.8v1.0.7.78v1.0.11.962024-03-07
CVE-2023-48725 [HIGH] CWE-121 CVE-2023-48725: A stack-based buffer overflow vulnerability exists in the JSON Parsing getblockschedule() functional
A stack-based buffer overflow vulnerability exists in the JSON Parsing getblockschedule() functionality of Netgear RAX30 1.0.11.96 and 1.0.7.78. A specially crafted HTTP request can lead to code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
nvd
CVE-2023-1327CRITICALCVSS 9.8fixed in 1.0.6.742023-03-14
CVE-2023-1327 [CRITICAL] CWE-287 CVE-2023-1327: Netgear RAX30 (AX2400), prior to version 1.0.6.74, was affected by an authentication bypass vulnerab
Netgear RAX30 (AX2400), prior to version 1.0.6.74, was affected by an authentication bypass vulnerability, allowing an unauthenticated attacker to gain administrative access to the device's web management interface by resetting the admin password.
nvd
CVE-2023-27852CRITICALCVSS 9.8fixed in 1.0.10.942023-03-10
CVE-2023-27852 [CRITICAL] CWE-120 CVE-2023-27852: NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a buffer overflow vulnerability in vario
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a buffer overflow vulnerability in various CGI mechanisms that could allow an attacker to execute arbitrary code on the device.
nvd
CVE-2023-27853CRITICALCVSS 9.8fixed in 1.0.10.942023-03-10
CVE-2023-27853 [CRITICAL] CWE-120 CVE-2023-27853: NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a format string vulnerability in a SOAP
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a format string vulnerability in a SOAP service that could allow an attacker to execute arbitrary code on the device.
nvd
CVE-2023-27851HIGHCVSS 8.8fixed in 1.0.10.942023-03-10
CVE-2023-27851 [HIGH] CVE-2023-27851: NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that unintentio
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that unintentionally allows users with upload permissions to execute arbitrary code on the device.
nvd
CVE-2023-1205HIGHCVSS 8.8fixed in 1.0.10.942023-03-10
CVE-2023-1205 [HIGH] CWE-352 CVE-2023-1205: NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 is vulnerable to cross-site request forgery attac
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 is vulnerable to cross-site request forgery attacks on all endpoints due to improperly implemented CSRF protections.
nvd
CVE-2023-27850MEDIUMCVSS 6.8fixed in 1.0.10.942023-03-10
CVE-2023-27850 [MEDIUM] CWE-59 CVE-2023-27850: NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that allows use
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that allows users with access to this feature to access arbitrary files on the device.
nvd
CVE-2022-47210HIGHCVSS 7.8fixed in 1.0.9.902022-12-16
CVE-2022-47210 [HIGH] CWE-78 CVE-2022-47210: The default console presented to users over telnet (when enabled) is restricted to a subset of comma
The default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, however, appear to be fed directly into a system call or other similar function. This allows any authenticated user to execute arbitrary commands on the device.
nvd
CVE-2022-47209HIGHCVSS 8.8fixed in 1.0.9.902022-12-16
CVE-2022-47209 [HIGH] CWE-287 CVE-2022-47209: A support user exists on the device and appears to be a backdoor for Technical Support staff. The de
A support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “support” and cannot be changed by a user via any normally accessible means.
nvd
← Previous2 / 2