PT-2025-30295 · NetGear · Netgear Rax30

Published

2025-07-21

·

Updated

2025-07-22

·

CVE-2025-44658

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Netgear RAX30 version 1.0.10.94
Description A PHP-FPM misconfiguration exists due to not restricting FPM to only process .php extensions. An attacker can exploit this by uploading malicious scripts with alternate extensions and tricking the web server into executing them as PHP, bypassing file extension-based security mechanisms. This may lead to remote code execution (RCE) or information disclosure.
Recommendations Update to a newer version that contains a fix for this issue. As a temporary workaround, restrict file uploads to only .php extensions.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2025-09549
CVE-2025-44658

Affected Products

Netgear Rax30