Netgear Xr1000 vulnerabilities
8 known vulnerabilities affecting netgear/xr1000.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM6
Vulnerabilities
Page 1 of 1
CVE-2025-25246P3HIGHCVSS 8.1fixed in 1.0.0.742025-02-05
CVE-2025-25246 [HIGH] CWE-94 CVE-2025-25246: NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote co
NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users.
nvd
CVE-2026-9213P3HIGHCVSS 8.1fixed in V1.0.2.862026-06-09
CVE-2026-9213 [HIGH] CWE-20 CVE-2026-9213: A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercep
A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device.
nvd
CVE-2021-34870P3MEDIUMCVSS 6.5v1.0.0.52_1.0.382022-01-25
CVE-2021-34870 [MEDIUM] CWE-306 CVE-2021-34870: This vulnerability allows network-adjacent attackers to disclose sensitive information on affected i
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR XR1000 1.0.0.52_1.0.38 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SOAP messages. The issue results from a lack of authentication required for a privi
nvd
CVE-2026-62657P4MEDIUMCVSS 4.9fixed in V1.0.2.862026-07-14
CVE-2026-62657 [MEDIUM] CWE-599 CVE-2026-62657: A security flaw in the router's certificate validation process was discovered in the NETGEAR XR1000
A security flaw in the router's certificate validation process was
discovered in the NETGEAR XR1000 Gaming Router and certain Nighthawk models that could allow an unauthorized person to remotely access and take
control of the device.
nvd
CVE-2026-0418P4MEDIUMCVSS 4.5fixed in v1.0.0.682026-06-09
CVE-2026-0418 [MEDIUM] CWE-15 CVE-2026-0418: Insufficient configuration management in the listed devices allows authenticated administrators conn
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network
to tamper with the system.
nvd
CVE-2026-0417P4MEDIUMCVSS 4.5fixed in V1.0.0.682026-06-09
CVE-2026-0417 [MEDIUM] CWE-20 CVE-2026-0417: Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated admin
Insufficient input validation vulnerability in the listed NETGEAR devices allows
authenticated administrators connected to the local network to tamper with
the router's integrity.
nvd
CVE-2026-9210P4MEDIUMCVSS 4.5fixed in V1.0.0.682026-06-09
CVE-2026-9210 [MEDIUM] CWE-20 CVE-2026-9210: Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated admini
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
nvd
CVE-2026-0410P4MEDIUMCVSS 4.5fixed in V1.1.0.222026-06-09
CVE-2026-0410 [MEDIUM] CWE-20 CVE-2026-0410: Authenticated administrators connected to the local network can gain elevated access to the router
Authenticated administrators connected to the local network can gain
elevated access to the router and make unauthorized changes to router
software and functionality.
nvd