216.73.217.22

CVE-2025-44658

· Published 21/07/2025 16:15 · Modified 22/07/2025 20:15

Labels: CVE-2025-44658 2025-07-21CVE-2025-44658CWE-434[email protected]

Essential information

Published
21/07/2025 16:15
Modified
22/07/2025 20:15
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions. An attacker may exploit this by uploading malicious scripts disguised with alternate extensions and tricking the web server into executing them as PHP, bypassing security mechanisms based on file extension filtering. This may lead to remote code execution (RCE), information disclosure, or full system compromise.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
netgear / rax30 cpe:2.3:a:netgear:rax30:1.0.10.94:*:*:*:*:*:*:*
netgear / rax30 cpe:2.3:a:netgear:rax30:*:*:*:*:*:*:*:*

References