CVE-2023-48725: NETGEAR RAX30 Firmware

High severity, CVSS 8.8. EPSS: 19.4% chance of exploitation in the next 30 days.

A stack-based buffer overflow vulnerability exists in the JSON Parsing getblockschedule() functionality of Netgear RAX30 1.0.11.96 and 1.0.7.78. A specially crafted HTTP request can lead to code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Affected products

  • NETGEAR RAX30 Firmware: version 1.0.7.78 only; version 1.0.11.96 only

Published 2024-03-07. Last modified 2026-06-17.