Netgear
Netgear Rax30 Firmware: vulnerabilidades y CVE
Netgear Rax30 Firmware tiene 36 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE36
Últimos 12 meses5
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-9216 | Baja (1.2) | 0.36% | — | 8 sept 2026 | An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no… |
| CVE-2026-11814 | Media (4.9) | 0.91% | — | 11 ago 2026 | A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality… |
| CVE-2026-11738 | Media (4.3) | 0.27% | — | 11 ago 2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality. |
| CVE-2026-9211 | Media (5.2) | 0.39% | — | 9 jun 2026 | An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation. |
| CVE-2025-12943 | Media (5.2) | 0.16% | — | 11 nov 2025 | Improper certificate validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router) and RAXE300 (Nighthawk AXE7800 Tri-Band WiFi 6E Router) allows attackers with the ability to… |
| CVE-2025-44652 | Alta (7.5) | 0.57% | — | 21 jul 2025 | In Netgear RAX30 V1.0.10.94_3, the USERLIMIT_GLOBAL option is set to 0 in multiple bftpd-related configuration files. This can cause DoS attacks when unlimited users are connected. |
| CVE-2025-44658 | Crítica (9.8) | 1.0% | — | 21 jul 2025 | In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions. An attacker may exploit this by uploading malicious scripts… |
| CVE-2023-51635 | Alta (8.8) | 1.3% | — | 22 nov 2024 | NETGEAR RAX30 fing_dil Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers.… |
| CVE-2023-51634 | Alta (7.5) | 0.57% | — | 22 nov 2024 | NETGEAR RAX30 Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of… |
| CVE-2023-40480 | Alta (8.8) | 1.3% | — | 3 may 2024 | NETGEAR RAX30 DHCP Server Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers.… |
| CVE-2023-40479 | Alta (8.8) | 1.3% | — | 3 may 2024 | NETGEAR RAX30 UPnP Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication… |
| CVE-2023-40478 | Media (6.8) | 0.83% | — | 3 may 2024 | NETGEAR RAX30 Telnet CLI passwd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30… |
| CVE-2023-35722 | Alta (8.8) | 1.3% | — | 3 may 2024 | NETGEAR RAX30 UPnP Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication… |
| CVE-2023-34285 | Alta (8.8) | 0.90% | — | 3 may 2024 | NETGEAR RAX30 cmsCli_authenticate Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR… |
| CVE-2023-34284 | Media (6.3) | 0.45% | — | 3 may 2024 | NETGEAR RAX30 Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR RAX30 routers.… |
| CVE-2023-34283 | Media (4.6) | 0.65% | — | 3 may 2024 | NETGEAR RAX30 USB Share Link Following Information Disclosure Vulnerability. This vulnerability allows physically present attackers to disclose sensitive information on affected installations of NETGEAR RAX30 routers.… |
| CVE-2023-27370 | Media (5.7) | 0.34% | — | 3 may 2024 | NETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR… |
| CVE-2023-27369 | Alta (8.8) | 0.78% | — | 3 may 2024 | NETGEAR RAX30 soap_serverd Stack-based Buffer Overflow Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30.… |
| CVE-2023-27368 | Alta (8.8) | 0.78% | — | 3 may 2024 | NETGEAR RAX30 soap_serverd Stack-based Buffer Overflow Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30… |
| CVE-2023-27367 | Alta (8) | 1.4% | — | 3 may 2024 | NETGEAR RAX30 libcms_cli Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Although… |
| CVE-2023-27361 | Alta (8) | 0.86% | — | 3 may 2024 | NETGEAR RAX30 rex_cgi JSON Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR… |
| CVE-2023-27360 | Alta (8.8) | 0.45% | — | 3 may 2024 | NETGEAR RAX30 lighttpd Misconfiguration Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30. Authentication is… |
| CVE-2023-27358 | Alta (8.8) | 0.88% | — | 3 may 2024 | NETGEAR RAX30 SOAP Request SQL Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers.… |
| CVE-2023-27357 | Media (6.5) | 0.57% | — | 3 may 2024 | NETGEAR RAX30 GetInfo Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR RAX30… |
| CVE-2023-27356 | Alta (8) | 1.2% | — | 3 may 2024 | NETGEAR RAX30 logCtrl Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Although… |
| CVE-2023-48725 | Alta (8.8) | 19% | — | 7 mar 2024 | A stack-based buffer overflow vulnerability exists in the JSON Parsing getblockschedule() functionality of Netgear RAX30 1.0.11.96 and 1.0.7.78. A specially crafted HTTP request can lead to code execution. An attacker… |
| CVE-2023-28338 | Alta (7.5) | 0.63% | — | 15 mar 2023 | Any request send to a Netgear Nighthawk Wifi6 Router (RAX30)'s web service containing a “Content-Type” of “multipartboundary=” will result in the request body being written to “/tmp/mulipartFile” on the device itself. A… |
| CVE-2023-28337 | Alta (8.8) | 0.72% | — | 15 mar 2023 | When uploading a firmware image to a Netgear Nighthawk Wifi6 Router (RAX30), a hidden “forceFWUpdate” parameter may be provided to force the upgrade to complete and bypass certain validation checks. End users can use… |
| CVE-2023-1327 | Crítica (9.8) | 0.87% | — | 14 mar 2023 | Netgear RAX30 (AX2400), prior to version 1.0.6.74, was affected by an authentication bypass vulnerability, allowing an unauthenticated attacker to gain administrative access to the device's web management interface by… |
| CVE-2023-27853 | Crítica (9.8) | 20% | — | 10 mar 2023 | NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a format string vulnerability in a SOAP service that could allow an attacker to execute arbitrary code on the device. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.