CVE-2024-35517: NETGEAR XR1000 Firmware

High severity, CVSS 7.2. EPSS: 15% chance of exploitation in the next 30 days.

Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter.

Affected products

  • NETGEAR XR1000 Firmware: version 1.0.0.64 only

Published 2024-10-11. Last modified 2026-06-17.