CVE-2025-4121: Netgear JWNR2000v2 cmd_wireless command injection
Published Apr 30, 2025
·Updated
A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been declared as critical. Affected by this vulnerability is the function cmdwireless. The manipulation of the argument host leads to command injection. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
3 affected components
Netgear JWNR2000v2
All of the following
Netgear Jwnr2000v2 Firmware=1.0.0.11
Netgear JWNR2000v2
Event History
Apr 30, 2025
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-4121?
CVE-2025-4121 is classified as a critical vulnerability.
2
What are the implications of exploiting CVE-2025-4121?
Exploiting CVE-2025-4121 can lead to remote command injection on the affected device.
3
Which device is affected by CVE-2025-4121?
The vulnerability CVE-2025-4121 affects the Netgear JWNR2000v2 router.
4
How do I mitigate CVE-2025-4121?
To mitigate CVE-2025-4121, it is recommended to update the firmware of the Netgear JWNR2000v2 to the latest version.
5
Can CVE-2025-4121 be exploited remotely?
Yes, CVE-2025-4121 is a vulnerability that can be exploited remotely.