A vulnerability, which was classified as critical, has been found in Netgear JWNR2000v2 1.0.0.11. Affected by this issue is the function get_cur_lang_ver. The manipulation of the argument host leads to buffer overflow. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
History

Fri, 16 May 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Netgear
Netgear jwnr2000
Netgear jwnr2000 Firmware
CPEs cpe:2.3:h:netgear:jwnr2000:v2:*:*:*:*:*:*:*
cpe:2.3:o:netgear:jwnr2000_firmware:1.0.0.11:*:*:*:*:*:*:*
Vendors & Products Netgear
Netgear jwnr2000
Netgear jwnr2000 Firmware

Wed, 30 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Apr 2025 13:00:00 +0000

Type Values Removed Values Added
Description A vulnerability, which was classified as critical, has been found in Netgear JWNR2000v2 1.0.0.11. Affected by this issue is the function get_cur_lang_ver. The manipulation of the argument host leads to buffer overflow. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Title Netgear JWNR2000v2 get_cur_lang_ver buffer overflow
Weaknesses CWE-119
CWE-120
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-04-30T13:28:22.057Z

Reserved: 2025-04-30T05:11:51.424Z

Link: CVE-2025-4116

cve-icon Vulnrichment

Updated: 2025-04-30T13:28:07.586Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-30T13:15:49.867

Modified: 2025-05-16T16:53:50.383

Link: CVE-2025-4116

cve-icon Redhat

No data.