CVE-2022-47210: NETGEAR RAX30 Firmware
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, however, appear to be fed directly into a system call or other similar function. This allows any authenticated user to execute arbitrary commands on the device.
Affected products
- NETGEAR RAX30 Firmware: before 1.0.9.90 (fixed in 1.0.9.90)
Published 2022-12-16. Last modified 2026-06-17.