PT-2025-30295 · NetGear · Netgear Rax30
Published
2025-07-21
·
Updated
2025-07-22
·
CVE-2025-44658
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Netgear RAX30 version 1.0.10.94
Description
A PHP-FPM misconfiguration exists due to not restricting FPM to only process
.php extensions. An attacker can exploit this by uploading malicious scripts with alternate extensions and tricking the web server into executing them as PHP, bypassing file extension-based security mechanisms. This may lead to remote code execution (RCE) or information disclosure.Recommendations
Update to a newer version that contains a fix for this issue. As a temporary workaround, restrict file uploads to only
.php extensions.Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear Rax30