CVE-2025-44652: High severity Netgear RAX30 vulnerability
Published Jul 21, 2025
·Updated
In Netgear RAX30 V1.0.10.943, the USERLIMITGLOBAL option is set to 0 in multiple bftpd-related configuration files. This can cause DoS attacks when unlimited users are connected.
Affected Software
3 affected components
Netgear RAX30
All of the following
Netgear RAX30 firmware=1.0.10.94_3
Netgear RAX30
Event History
Jul 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-44652?
CVE-2025-44652 is considered a high severity vulnerability due to the potential for denial-of-service attacks when unlimited users connect.
2
How do I fix CVE-2025-44652?
To fix CVE-2025-44652, update the firmware of the Netgear RAX30 to the latest version provided by the vendor.
3
What products are affected by CVE-2025-44652?
CVE-2025-44652 affects the Netgear RAX30 router, specifically versions prior to V1.0.10.94_3.
4
What impact does CVE-2025-44652 have on network security?
CVE-2025-44652 can lead to denial-of-service conditions, impacting network availability and performance.
5
How can I mitigate CVE-2025-44652 until a fix is applied?
To mitigate CVE-2025-44652, limit the number of users who can connect to the Netgear RAX30 and monitor user activity closely.