Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m92m-qpp4-8jc8

Опубликовано: 21 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions. An attacker may exploit this by uploading malicious scripts disguised with alternate extensions and tricking the web server into executing them as PHP, bypassing security mechanisms based on file extension filtering. This may lead to remote code execution (RCE), information disclosure, or full system compromise.

In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions. An attacker may exploit this by uploading malicious scripts disguised with alternate extensions and tricking the web server into executing them as PHP, bypassing security mechanisms based on file extension filtering. This may lead to remote code execution (RCE), information disclosure, or full system compromise.

EPSS

Процентиль: 44%
0.00214
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
7 месяцев назад

In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions. An attacker may exploit this by uploading malicious scripts disguised with alternate extensions and tricking the web server into executing them as PHP, bypassing security mechanisms based on file extension filtering. This may lead to remote code execution (RCE), information disclosure, or full system compromise.

CVSS3: 9.8
fstec
7 месяцев назад

Уязвимость обработчика PHP-FPM (FastCGI Process Manager) микропрограммного обеспечения маршрутизаторов Nighthawk WiFi 6 Router (RAX30, позволяющая нарушителю обойти ограничения безопасности, выполнить произвольный код и получить полный контроль над системой

EPSS

Процентиль: 44%
0.00214
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434