CVE-2026-9215: NETGEAR XR1000 Firmware
Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.
A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality impact due to this vulnerability.
Affected products
- NETGEAR XR1000 Firmware: before 1.1.0.22 (fixed in 1.1.0.22)
- NETGEAR XR1000V2 Firmware: before 1.1.0.22 (fixed in 1.1.0.22)
- NETGEAR XR500 Firmware: before 2.3.5.152 (fixed in 2.3.5.152)
Published 2026-09-08. Last modified 2026-09-11.