Netgear Jwnr2000V2 Firmware vulnerabilities

5 known vulnerabilities affecting netgear/jwnr2000v2_firmware.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2025-4120HIGHCVSS 8.7v1.0.0.112025-04-30
CVE-2025-4120 [HIGH] CWE-119 CVE-2025-4120: A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been classified as critical. Affect A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been classified as critical. Affected is the function sub_4238E8. The manipulation of the argument host leads to buffer overflow. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
nvd
CVE-2025-4121MEDIUMCVSS 5.3v1.0.0.112025-04-30
CVE-2025-4121 [MEDIUM] CWE-74 CVE-2025-4121: A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been declared as critical. Affected A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been declared as critical. Affected by this vulnerability is the function cmd_wireless. The manipulation of the argument host leads to command injection. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
nvd
CVE-2025-4122MEDIUMCVSS 5.3v1.0.0.112025-04-30
CVE-2025-4122 [MEDIUM] CWE-74 CVE-2025-4122: A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been rated as critical. Affected by A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been rated as critical. Affected by this issue is the function sub_435E04. The manipulation of the argument host leads to command injection. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
nvd
CVE-2023-38922HIGHCVSS 8.8v1.0.0.112023-08-07
CVE-2023-38922 [HIGH] CWE-120 CVE-2023-38922: Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 were discovered to contain m Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 were discovered to contain multiple buffer overflows via the http_passwd and http_username parameters in the update_auth function.
nvd
CVE-2023-39550HIGHCVSS 8.8v1.0.0.112023-08-07
CVE-2023-39550 [HIGH] CWE-120 CVE-2023-39550: Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 were discovered to contain m Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 were discovered to contain multiple buffer overflows via the http_passwd and http_username parameters in the check_auth function.
nvd