CVE-2025-44650: NETGEAR EAX80 Firmware
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf configuration file. This can cause DoS attacks when unlimited users are connected.
Affected products
- NETGEAR EAX80 Firmware: version 1.0.1.70_1.0.2 only
- NETGEAR r7000 Firmware: version 1.3.1.64_10.1.36 only
Published 2025-07-21. Last modified 2026-06-17.