NETGEAR RAX30 lighttpd Misconfiguration Remote Code Execution Vulnerability

Rocco Calvi

ZDI ID: ZDI-23-496
ZDI-CAN: ZDI-CAN-19398
CVSS
7.5 AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Vendors
NETGEAR
Affected Products
RAX30

Additional Details

Disclosure Timeline

  • 2022-11-30 — Vulnerability reported to vendor
  • 2023-05-01 — Coordinated public release of advisory