CVE-2025-4122
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Apr 30, 2025
Updated: May 12, 2025
CWE ID 77
CWE ID 74
Summary
CVE-2025-4122 is a critical vulnerability identified in the Netgear JWNR2000v2 1.0.0.11 firmware. The issue lies within the function sub_435E04 and allows an attacker to inject commands through manipulation of the host argument. This vulnerability enables remote command injection, posing a significant security risk. Despite early disclosure to the vendor, no response or patch has been provided.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Netgear, Inc.