CVE-2026-9215
Awaiting Analysis
Awaiting Analysis - Queue
Cross-Site Request Forgery in NETGEAR Router Firmware
Vulnerability report for CVE-2026-9215, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-08
Last updated on: 2026-09-09
Assigner: Netgear, Inc.
Description
Description
A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality impact due to this vulnerability.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| netgear | xr1000 | 1.1.0.22 |
| netgear | xr1000v2 | 1.1.0.22 |
| netgear | xr500 | 2.3.5.152 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-352 | The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor. |