CVE-2022-47210: NETGEAR RAX30 Firmware

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, however, appear to be fed directly into a system call or other similar function. This allows any authenticated user to execute arbitrary commands on the device.

Affected products

  • NETGEAR RAX30 Firmware: before 1.0.9.90 (fixed in 1.0.9.90)

Published 2022-12-16. Last modified 2026-06-17.