Vulnerabilities > Netgear > Rax30 Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2023-03-15 CVE-2023-28337 Unrestricted Upload of File with Dangerous Type vulnerability in Netgear Rax30 Firmware
When uploading a firmware image to a Netgear Nighthawk Wifi6 Router (RAX30), a hidden “forceFWUpdate” parameter may be provided to force the upgrade to complete and bypass certain validation checks.
network
low complexity
netgear CWE-434
8.8
2023-03-15 CVE-2023-28338 Allocation of Resources Without Limits or Throttling vulnerability in Netgear Rax30 Firmware
Any request send to a Netgear Nighthawk Wifi6 Router (RAX30)'s web service containing a “Content-Type” of “multipartboundary=” will result in the request body being written to “/tmp/mulipartFile” on the device itself.
network
low complexity
netgear CWE-770
7.5
2023-03-10 CVE-2023-1205 Cross-Site Request Forgery (CSRF) vulnerability in Netgear Rax30 Firmware
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 is vulnerable to cross-site request forgery attacks on all endpoints due to improperly implemented CSRF protections.
network
low complexity
netgear CWE-352
8.8
2023-03-10 CVE-2023-27851 Unspecified vulnerability in Netgear Rax30 Firmware
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that unintentionally allows users with upload permissions to execute arbitrary code on the device.
network
low complexity
netgear
8.8
2022-12-16 CVE-2022-47209 Improper Authentication vulnerability in Netgear Rax30 Firmware
A support user exists on the device and appears to be a backdoor for Technical Support staff.
low complexity
netgear CWE-287
8.8
2022-12-16 CVE-2022-47210 OS Command Injection vulnerability in Netgear Rax30 Firmware
The default console presented to users over telnet (when enabled) is restricted to a subset of commands.
local
low complexity
netgear CWE-78
7.8