In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf configuration file. This can cause DoS attacks when unlimited users are connected.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://www.netgear.com/about/security/ | vendor advisory |
https://gist.github.com/TPCchecker/d13d15dfa8965ba88a9437718f77f67d | broken link |
https://www.notion.so/CVE-2025-44650-24754a1113e780dca89dca218b90b1d9 | third party advisory |