Netgear JWNR2000v2 Buffer Overflow Vulnerability in Function sub_41A914

Vulnerability

A critical buffer overflow vulnerability has been identified in the Netgear JWNR2000v2 router, specifically in version 1.0.0.11. The issue arises in the function sub_41A914, where improper handling of the 'host' argument creates the potential for memory corruption. This vulnerability was disclosed to the vendor, but no response was received.

Impact

Exploitation of this vulnerability leads to a buffer overflow, which can commonly result in arbitrary code execution or causing a denial-of-service condition.

Reproduction

The vulnerability can be reproduced by sending a crafted request to the router's web interface that includes a 'host' argument. The manipulation of this argument triggers the buffer overflow in the affected function.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
7.5
exploitability
5.2
remediation
0.0
relevance
0.0
threat
1.6
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.