🔐 CVE Alert

CVE-2026-9215

MEDIUM 6.7

A CSRF vulnerability exists in certain NETGEAR XR series devices

CVSS Score
6.7
EPSS Score
0.0%
EPSS Percentile
0th

A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality impact due to this vulnerability.

CWE CWE-352
Vendor netgear
Product xr1000
Published Sep 8, 2026
Last Updated Sep 9, 2026
Stay Ahead of the Next One

Get instant alerts for netgear xr1000

Be the first to know when new medium vulnerabilities affecting netgear xr1000 are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High

Affected Versions

NETGEAR / XR1000
0 < V1.1.0.22
NETGEAR / XR1000v2
0 < V1.1.0.22
NETGEAR / XR500
0 < v2.3.5.152

References

NVD ↗ CVE.org ↗ EPSS Data ↗
netgear.com: https://www.netgear.com/support/product/xr500 netgear.com: https://www.netgear.com/support/product/xr1000 netgear.com: https://www.netgear.com/support/product/xr1000v2 kb.netgear.com: https://kb.netgear.com/000070912/September-2026-NETGEAR-Security-Advisory

Credits

mornaner