6.7
CVE-2026-9215
- EPSS 0.12%
- Veröffentlicht 08.09.2026 17:06:47
- Zuletzt bearbeitet 11.09.2026 21:20:24
- Erkennungen
A CSRF vulnerability exists in certain NETGEAR XR series devices
A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality impact due to this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netgear ≫ Xr1000 Firmware Version < 1.1.0.22
Netgear ≫ Xr1000v2 Firmware Version < 1.1.0.22
Netgear ≫ Xr500 Firmware Version < 2.3.5.152
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.02 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NETGEAR | 1.8 | 0 | 0 |
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:D/RE:L/U:Amber
|
| NETGEAR | 6.7 | 1.5 | 5.2 |
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
https://www.netgear.com/support/product/xr1000v2
https://www.netgear.com/support/product/xr500
https://www.netgear.com/support/product/xr1000
https://kb.netgear.com/000070912/September-2026-NETGEAR-Security-Advisory