CVE-2025-44658
Last modified
CVE-2025-44658 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions. An attacker may exploit this by uploading malicious scripts disguised with alternate extensions and tricking the web server into executing them as PHP, bypassing security mechanisms based on file extension filtering. EPSS estimates a 1.01% chance of exploitation in the next 30 days.
Description
In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions. An attacker may exploit this by uploading malicious scripts disguised with alternate extensions and tricking the web server into executing them as PHP, bypassing security mechanisms based on file extension filtering. This may lead to remote code execution (RCE), information disclosure, or full system compromise.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Rax30 Firmware | 1.0.10.94 |
References
- https://www.netgear.com/about/security/Vendor Advisory
- https://www.notion.so/CVE-2025-44658-24754a1113e780df8f72c779a108f75bThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-44658?
How severe is CVE-2025-44658?
How do I fix CVE-2025-44658?
Are you affected by CVE-2025-44658?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
