Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: ProductFixed VersionXR1000 Nighthawk WiFi 6 Pro Gaming Router V1.1.0.22 https://www.netgear.com/support/product/xr1000 XR1000v2 Nighthawk WiFi 6 Pro Gaming Router V1.1.0.22 https://www.netgear.com/support/product/xr1000v2 XR500 (EoS) Nighthawk Pro Gaming Router v2.3.5.152 https://www.netgear.com/support/product/xr500 Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality impact due to this vulnerability. | |
| Title | A CSRF vulnerability exists in certain NETGEAR XR series devices | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: NETGEAR
Published:
Updated: 2026-09-08T18:26:22.205Z
Reserved: 2026-05-21T17:29:08.100Z
Link: CVE-2026-9215
No data.
Status : Received
Published: 2026-09-08T18:21:17.893
Modified: 2026-09-08T18:21:17.893
Link: CVE-2026-9215
No data.
OpenCVE Enrichment
No data.
-
CWE-352
Cross-Site Request Forgery (CSRF)