CVE-2026-9215
A CSRF vulnerability exists in certain NETGEAR XR series devices
CVSS Score
6.7
EPSS Score
0.0%
EPSS Percentile
0th
A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality impact due to this vulnerability.
| CWE | CWE-352 |
| Vendor | netgear |
| Product | xr1000 |
| Published | Sep 8, 2026 |
| Last Updated | Sep 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for netgear xr1000
Be the first to know when new medium vulnerabilities affecting netgear xr1000 are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High
Affected Versions
NETGEAR / XR1000
0 < V1.1.0.22
NETGEAR / XR1000v2
0 < V1.1.0.22
NETGEAR / XR500
0 < v2.3.5.152
References
Credits
mornaner