CVE-2025-25246: NETGEAR XR1000
High severity, CVSS 8.1. EPSS: 0.7% chance of exploitation in the next 30 days.
NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users.
Affected products
- NETGEAR XR1000: before 1.0.0.74 (fixed in 1.0.0.74)
- NETGEAR XR1000V2: before 1.1.0.22 (fixed in 1.1.0.22)
- NETGEAR XR500: before 2.3.2.134 (fixed in 2.3.2.134)
Published 2025-02-05. Last modified 2026-06-17.