CVE-2022-47209: NETGEAR RAX30 Firmware

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “support” and cannot be changed by a user via any normally accessible means.

Affected products

  • NETGEAR RAX30 Firmware: before 1.0.9.90 (fixed in 1.0.9.90)

Published 2022-12-16. Last modified 2026-06-17.