CVE-2026-9215 LOW

CVE-2026-9215: A CSRF vulnerability exists in certain NETGEAR XR series devices

Vendor Netgear
Product XR1000
Weakness CWE-352 · CSRF
Published September 8, 2026
Last update September 9, 2026

CVSS base score

1.8/10
Attack vector Adjacent
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/V:D/RE:L/U:Amber

What the vulnerability does

01Description

A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality impact due to this vulnerability.

Key dates

02Disclosure timeline

September 8, 2026 CVE published
September 9, 2026 Record updated

Related vulnerabilities

04Related CVE