Junglewise Threat Intelligence

CVE-2026-9215: NETGEAR XR gaming routers CSRF vulnerability

CVE-2026-9215 · Severity: medium · CVSS 6.7 · Published 2026-09-08

Executive brief

NETGEAR's gaming routers contain a cross-site request forgery (CSRF) flaw that allows attackers to manipulate router configuration settings if they trick an administrator into visiting a malicious website. While an attacker cannot directly extract data or gain unauthorized access, they can disrupt router operations and modify settings—requiring the administrator's active participation through social engineering. This could degrade network performance or lock legitimate users out of configuration.

Technical details

A CSRF vulnerability in NETGEAR XR-series gaming routers allows attackers to forge requests that modify router configuration when a logged-in administrator visits an attacker-controlled webpage. The vulnerability requires social engineering to trick the router administrator into visiting the malicious site while authenticated to the router's management interface. An attacker can tamper with router settings and disrupt operations, though the vulnerability carries no confidentiality impact and requires active assistance from the administrator. Patches are available: XR1000 and XR1000v2 are fixed in firmware version 1.1.0.22, while XR500 (end-of-support) is fixed in version 2.3.5.152.

Affected products

  • NETGEAR XR1000 before 1.1.0.22
  • NETGEAR XR1000v2 before 1.1.0.22
  • NETGEAR XR500 before 2.3.5.152

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: patched: Firmware updates available for XR1000, XR1000v2, and XR500

References

Related threats