CVE-2025-25246: NETGEAR XR1000

High severity, CVSS 8.1. EPSS: 0.7% chance of exploitation in the next 30 days.

NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users.

Affected products

  • NETGEAR XR1000: before 1.0.0.74 (fixed in 1.0.0.74)
  • NETGEAR XR1000V2: before 1.1.0.22 (fixed in 1.1.0.22)
  • NETGEAR XR500: before 2.3.2.134 (fixed in 2.3.2.134)

Published 2025-02-05. Last modified 2026-06-17.