CVE-2026-9215EPSS p8.3%

CVE-2026-9215CVE-2026-9215

netgear / xr1000_firmware

Description

A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality impact due to this vulnerability.

Scoring

CVSS 6.7 ()
VectorCVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
EPSS0.19% probability of exploitation · percentile 8.3% · 2026-10-05T12:00:23Z
Last modified2026-09-11
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.