CVE-2025-4115

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 30, 2025
Updated: May 2, 2025
CWE ID 119
CWE ID 120

Summary

CVE-2025-4115 is a critical vulnerability affecting the Netgear JWNR2000v2 1.0.0.11 firmware. The issue lies in the function "default_version_is_new," which can be exploited through buffer overflow when the argument "host" is manipulated. This vulnerability allows for remote attacks, posing a significant risk to affected devices. Despite early disclosure of this issue to the vendor, they have not responded or taken any action to address the vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share