CVE-2025-44658

In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions. An attacker may exploit this by uploading malicious scripts disguised with alternate extensions and tricking the web server into executing them as PHP, bypassing security mechanisms based on file extension filtering. This may lead to remote code execution (RCE), information disclosure, or full system compromise.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:rax30_firmware:1.0.10.94:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax30:-:*:*:*:*:*:*:*

History

07 Aug 2025, 17:57

Type Values Removed Values Added
First Time Netgear rax30
Netgear
Netgear rax30 Firmware
CPE cpe:2.3:h:netgear:rax30:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rax30_firmware:1.0.10.94:*:*:*:*:*:*:*
References () https://www.notion.so/CVE-2025-44658-24754a1113e780df8f72c779a108f75b - () https://www.notion.so/CVE-2025-44658-24754a1113e780df8f72c779a108f75b - Third Party Advisory
References () https://gist.github.com/TPCchecker/c72eea7a3f89070dab7dfdbf7504b2d6 - () https://gist.github.com/TPCchecker/c72eea7a3f89070dab7dfdbf7504b2d6 - Broken Link
References () https://www.netgear.com/about/security/ - () https://www.netgear.com/about/security/ - Vendor Advisory

07 Aug 2025, 14:15

Type Values Removed Values Added
References
  • () https://www.notion.so/CVE-2025-44658-24754a1113e780df8f72c779a108f75b -

21 Jul 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-21 16:15

Updated : 2025-08-07 17:57


NVD link : CVE-2025-44658

Mitre link : CVE-2025-44658


JSON object : View

Products Affected

netgear

  • rax30_firmware
  • rax30
CWE

No CWE.