CVE-2025-44650: High severity Netgear R7000 vulnerability
Published Jul 21, 2025
·Updated
In Netgear R7000 V1.3.1.6410.1.36 and EAX80 V1.0.1.701.0.2, the USERLIMITGLOBAL option is set to 0 in the bftpd.conf configuration file. This can cause DoS attacks when unlimited users are connected.
Affected Software
6 affected components
Netgear R7000
Netgear EAX80
All of the following
Netgear R7000 Firmware=1.3.1.64_10.1.36
Netgear R7000
All of the following
Netgear Eax80 Firmware=1.0.1.70_1.0.2
Netgear EAX80
Event History
Jul 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-44650?
CVE-2025-44650 has a high severity due to its potential to cause denial of service attacks.
2
How do I fix CVE-2025-44650?
To fix CVE-2025-44650, update the bftpd.conf configuration file to set the USERLIMIT_GLOBAL option to a non-zero value.
3
Which devices are affected by CVE-2025-44650?
CVE-2025-44650 affects Netgear R7000 and Netgear EAX80 devices.
4
Can CVE-2025-44650 be exploited remotely?
Yes, CVE-2025-44650 can be exploited remotely if unlimited user connections are allowed.
5
What are the potential impacts of CVE-2025-44650?
CVE-2025-44650 can lead to service interruptions and denial of service due to potential overload of the device.