CVE-2026-9215 PUBLISHED

A CSRF vulnerability exists in certain NETGEAR XR series devices

Assigner: NETGEAR
Reserved: 21.05.2026 Published: 08.09.2026 Updated: 09.09.2026

A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality impact due to this vulnerability.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/V:D/RE:L/U:Amber
CVSS Score: 1.8

Product Status

Vendor NETGEAR
Product XR1000
Versions Default: unaffected
  • affected from 0 to V1.1.0.22 (excl.)
Vendor NETGEAR
Product XR1000v2
Versions Default: unaffected
  • affected from 0 to V1.1.0.22 (excl.)
Vendor NETGEAR
Product XR500
Versions Default: unaffected
  • affected from 0 to v2.3.5.152 (excl.)

Solutions

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in:

ProductFixed VersionXR1000 Nighthawk WiFi 6 Pro Gaming Router V1.1.0.22 https://www.netgear.com/support/product/xr1000 XR1000v2 Nighthawk WiFi 6 Pro Gaming Router V1.1.0.22 https://www.netgear.com/support/product/xr1000v2 XR500 (EoS) Nighthawk Pro Gaming Router v2.3.5.152 https://www.netgear.com/support/product/xr500

Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

Credits

  • mornaner finder

References

Problem Types

  • CWE-352 Cross-Site request forgery (CSRF) CWE