CVE-2026-9215
6.4
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
Summary
A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality impact due to this vulnerability.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NETGEAR | XR1000 | 0 < V1.1.0.22 | affected |
| NETGEAR | XR1000v2 | 0 < V1.1.0.22 | affected |
| NETGEAR | XR500 | 0 < v2.3.5.152 | affected |
Weaknesses
- CWE-352: CWE-352 Cross-Site request forgery (CSRF)
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://www.netgear.com/support/product/xr500
- https://www.netgear.com/support/product/xr1000
- https://www.netgear.com/support/product/xr1000v2
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.