LOW 1.8 NVD
CVE-2026-9215
A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router adm
A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality impact due to this vulnerability.
Affected Products
- netgear/xr1000
- netgear/xr1000_firmware
- netgear/xr1000v2
- netgear/xr1000v2_firmware
- netgear/xr500
- netgear/xr500_firmware
References
- https://kb.netgear.com/000070912/September-2026-NETGEAR-Security-Advisory
- https://www.netgear.com/support/product/xr1000
- https://www.netgear.com/support/product/xr1000v2
- https://www.netgear.com/support/product/xr500
This low severity vulnerability with a CVSS score of 1.8 was published on 2026-09-08 via NVD. Affected: netgear/xr1000, netgear/xr1000_firmware, netgear/xr1000v2 and 3 more.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.