The default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, however, appear to be fed directly into a system call or other similar function. This allows any authenticated user to execute arbitrary commands on the device.
2022-12-16T20:15:09.003
2025-04-17T19:15:54.927
Modified
CVSSv3.1: 7.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | netgear | rax30_firmware | < 1.0.9.90 | Yes |
Hardware | netgear | rax30 | - | No |