CVE-2025-4139

Published Apr 30, 2025

Last updated 2 months ago

Overview

Description
A vulnerability classified as critical was found in Netgear EX6120 1.0.0.68. Affected by this vulnerability is the function fwAcosCgiInbound. The manipulation of the argument host leads to buffer overflow. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Source
cna@vuldb.com
NVD status
Awaiting Analysis

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.7
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

CVSS 2.0

Type
Secondary
Base score
9
Impact score
10
Exploitability score
8
Vector string
AV:N/AC:L/Au:S/C:C/I:C/A:C

Weaknesses

cna@vuldb.com
CWE-119

Social media

Hype score
Not currently trending
  1. 🔴 Netgear EX6120, Buffer Overflow, #CVE-2025-4139 (Critical) https://t.co/SZwkshiRO5

    @dailycve

    23 Jun 2025

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 CVE-2025-4139 🔴 HIGH (8.7) 🏢 Netgear - EX6120 🏗️ 1.0.0.68 🔗 https://t.co/3MfDcDLCE3 🔗 https://t.co/WMWWGv59oz 🔗 https://t.co/lYKRr9HQF7 🔗 https://t.co/x9BiNxXkCU 🔗 https://t.co/7bUbFOnm4c #CyberCron #VulnAlert #InfoSec https://t.co/dGfMCReXHo

    @cybercronai

    1 May 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Netgear EX6200 Routers (v1.0.3.94) affected by multiple RCE including CVE-2025-4142 through 4150 in EX6200 routers. EX6120 separately affected by CVE-2025-4139 through 4141. https://t.co/bYN83XClrC

    @router_bugs

    1 May 2025

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. �� CVE-2025-4139 - NETGEAR EX6120 Extender - HIGH 🚨 🗓️ Date published 2025-04-30 21:15:55 UTC #NETGEAREX6120Extender #CyberSecurity #InfoSec #Vulnerability #TechNews https://t.co/ZNSj4imiqO

    @vulns_space

    30 Apr 2025

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. [CVE-2025-4139: HIGH] Critical #CyberSecurity: Vulnerability in Netgear EX6120 1.0.0.68 allows remote buffer overflow via fwAcosCgiInbound. Vendor notified with no response. Take caution.#cve,CVE-2025-4139,#cybersecurity https://t.co/CV7mYQGY6U https://t.co/zHuQhpOIYA

    @CveFindCom

    30 Apr 2025

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2025-4139 A vulnerability classified as critical was found in Netgear EX6120 1.0.0.68. Affected by this vulnerability is the function fwAcosCgiInbound. The manipulation of the ar… https://t.co/mT8WVGFeMe

    @CVEnew

    30 Apr 2025

    386 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    3 Replies

    1 Quote