March 10, 2023, 4:32 p.m. | Evan Grant

Tenable Research Advisories www.tenable.com

Authentication Bypass in Netgear RAX30 (AX2400) < 1.0.6.74

A researcher at Tenable discovered a previously undisclosed Authentication Bypass issue in the Netgear RAX30 (AX2400) router version 1.0.5.70. Tenable determined that the issue had been fixed in firmware version 1.0.6.74, but that it had not been explicitly acknowledged in the release notes for that firmware.


The vulnerability exists as the password reset form /pwd_reset/pwd_reset_passwordReset.html, and POST requests to /pwd_reset/reset_pwd.cgi did not require any form of authentication to reset the admin …

authentication authentication bypass bypass firmware issue netgear release release notes researcher router tenable version version 1

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC