NETGEAR Vulnerabilities and Affected Products
Vulnerabilities associated with JWNR2000v2.
Products
Clear product- r7000p_firmware27 vulnerabilities
- r8500_firmware25 vulnerabilities
- xr300_firmware25 vulnerabilities
- ProSAFE Network Management System23 vulnerabilities
- RAX3022 vulnerabilities
- r6400_firmware17 vulnerabilities
- SRX530817 vulnerabilities
- prosafe_network_management_system16 vulnerabilities
- RAX4315 vulnerabilities
- rax30_firmware14 vulnerabilities
- RAX5013 vulnerabilities
- RAXE50013 vulnerabilities
- R670012 vulnerabilities
- XR100012 vulnerabilities
- RAX4211 vulnerabilities
- RAX4511 vulnerabilities
- Multiple Routers10 vulnerabilities
- RAX4110 vulnerabilities
- EX62009 vulnerabilities
- JWNR2000v29 vulnerabilities
- R6700v39 vulnerabilities
- R70009 vulnerabilities
- R78009 vulnerabilities
- RAX209 vulnerabilities
- RAX54Sv29 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-4122MEDIUM | Netgear JWNR2000v2 sub_435E04 command injectionA vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been rated as critical. Affected by this issue is the function sub_435E04. The manipulation of the argument host leads to command injection. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS5.3v4.0 | EPSS2.6% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-4121MEDIUM | Netgear JWNR2000v2 cmd_wireless command injectionA vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been declared as critical. Affected by this vulnerability is the function cmd_wireless. The manipulation of the argument host leads to command injection. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS5.3v4.0 | EPSS2.75% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-4120HIGH | Netgear JWNR2000v2 sub_4238E8 buffer overflowA vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been classified as critical. Affected is the function sub_4238E8. The manipulation of the argument host leads to buffer overflow. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS8.7v4.0 | EPSS0.933% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-4117MEDIUM | Netgear JWNR2000v2 sub_41A914 buffer overflowA vulnerability, which was classified as critical, was found in Netgear JWNR2000v2 1.0.0.11. This affects the function sub_41A914. The manipulation of the argument host leads to buffer overflow. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS5.1v4.0 | EPSS0.643% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-4116HIGH | Netgear JWNR2000v2 get_cur_lang_ver buffer overflowA vulnerability, which was classified as critical, has been found in Netgear JWNR2000v2 1.0.0.11. Affected by this issue is the function get_cur_lang_ver. The manipulation of the argument host leads to buffer overflow. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS8.7v4.0 | EPSS0.921% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-4115HIGH | Netgear JWNR2000v2 default_version_is_new buffer overflowA vulnerability classified as critical was found in Netgear JWNR2000v2 1.0.0.11. Affected by this vulnerability is the function default_version_is_new. The manipulation of the argument host leads to buffer overflow. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS8.7v4.0 | EPSS0.921% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-4114HIGH | Netgear JWNR2000v2 check_language_file buffer overflowA vulnerability classified as critical has been found in Netgear JWNR2000v2 1.0.0.11. Affected is the function check_language_file. The manipulation of the argument host leads to buffer overflow. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS8.7v4.0 | EPSS1.01% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-38922HIGH | Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 were discovered to contain multiple buffer overflows via the http_passwd and http_username parameters in the update_auth function. CWE-120Aug 7, 2023 | CVSS8.8v3.1 | EPSS0.759% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-39550HIGH | Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 were discovered to contain multiple buffer overflows via the http_passwd and http_username parameters in the check_auth function. CWE-120Aug 7, 2023 | CVSS8.8v3.1 | EPSS1.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |