Vulnerabilities (CVE)

Filtered by vendor Netgear Subscribe
Filtered by product Rax30
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-47209 1 Netgear 2 Rax30, Rax30 Firmware 2023-08-08 N/A 8.8 HIGH
A support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “support” and cannot be changed by a user via any normally accessible means.
CVE-2022-47210 1 Netgear 2 Rax30, Rax30 Firmware 2023-08-08 N/A 7.8 HIGH
The default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, however, appear to be fed directly into a system call or other similar function. This allows any authenticated user to execute arbitrary commands on the device.