ZeroHour

CVE-2026-9215

CVSS 4.0
1.8 low
EPSS
<1%p2
Published
()
Modified
Description

A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality impact due to this vulnerability.

Vendors
netgear
Products
xr1000 firmware, xr1000v2 firmware, xr500 firmware
Weakness
CWE-352
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:D/RE:L/U:Amber

In the news

No ingested article mentions this CVE yet.