A stack-based buffer overflow vulnerability exists in the JSON Parsing getblockschedule() functionality of Netgear RAX30 1.0.11.96 and 1.0.7.78. A specially crafted HTTP request can lead to code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
2024-03-07T15:15:07.733
2025-03-11T16:56:47.143
Analyzed
CVSSv3.1: 7.2 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | netgear | rax30_firmware | 1.0.7.78 | Yes |
Operating System | netgear | rax30_firmware | 1.0.11.96 | Yes |
Hardware | netgear | rax30 | - | No |