CVE-2025-4140
published 2025-04-30CVE-2025-4140: A vulnerability, which was classified as critical, has been found in Netgear EX6120 1.0.3.94. Affected by this issue is the function sub_30394. The…
PriorityP259critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.97%
57.8th percentile
A vulnerability, which was classified as critical, has been found in Netgear EX6120 1.0.3.94. Affected by this issue is the function sub_30394. The manipulation of the argument host leads to buffer overflow. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | ex6120 | — | — |
| netgear | ex6120_firmware | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_oracle7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mf3m-m2fx-pq76: A vulnerability, which was classified as critical, has been found in Netgear EX6120 1
ghsa_unreviewed·2025-05-01
CVE-2025-4140 [HIGH] CWE-119 GHSA-mf3m-m2fx-pq76: A vulnerability, which was classified as critical, has been found in Netgear EX6120 1
A vulnerability, which was classified as critical, has been found in Netgear EX6120 1.0.3.94. Affected by this issue is the function sub_30394. The manipulation of the argument host leads to buffer overflow. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Oracle
Oracle Oracle Siebel CRM Risk Matrix: Keyword Automation (Email-MIME) — CVE-2024-4140
vendor_oracle·2025-10-15·CVSS 7.5
CVE-2024-4140 [HIGH] Oracle Oracle Siebel CRM Risk Matrix: Keyword Automation (Email-MIME) — CVE-2024-4140
Oracle Oracle Siebel CRM Risk Matrix: Keyword Automation (Email-MIME) vulnerability
CVE: CVE-2024-4140
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-30
Published