Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2026-9215 Details
Description
A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality impact due to this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CNA: Netgear, Inc.CVSS-B:5.2 MEDIUMVector:CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 8, 2026Exploitation: NoneAutomatable: NoTechnical Impact: Partial
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.netgear.com/000070912/September-2026-NETGEAR-Security-Advisory | Netgear, Inc. | Vendor Advisory |
| https://www.netgear.com/support/product/xr1000 | Netgear, Inc. | Product |
| https://www.netgear.com/support/product/xr1000v2 | Netgear, Inc. | Product |
| https://www.netgear.com/support/product/xr500 | Netgear, Inc. | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | Netgear, Inc. |
Affected Products
| Product | Versions |
|---|---|
| netgear xr1000 firmware | < 1.1.0.22 |
CPE
Remediation
| |
| netgear xr1000 | All versions |
CPE
Remediation
| |
| netgear xr1000v2 firmware | < 1.1.0.22 |
CPE
Remediation
| |
| netgear xr1000v2 | All versions |
CPE
Remediation
| |
| netgear xr500 firmware | < 2.3.5.152 |
CPE
Remediation
| |
| netgear xr500 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | Initial Analysis | [email protected] |
| Sep 9, 2026 | CVE Modified | Netgear, Inc. |
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | Netgear, Inc. |