Netgear Xr1000V2 vulnerabilities
7 known vulnerabilities affecting netgear/xr1000v2.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2025-25246P3HIGHCVSS 8.1fixed in 1.1.0.222025-02-05
CVE-2025-25246 [HIGH] CWE-94 CVE-2025-25246: NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote co
NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users.
nvd
CVE-2026-0406P3HIGHCVSS 8.0≤ 1.1.0.222026-01-13
CVE-2026-0406 [HIGH] CWE-20 CVE-2026-0406: An insufficient input validation vulnerability in the NETGEAR XR1000v2 allows attackers connected t
An insufficient input validation vulnerability in the NETGEAR XR1000v2
allows attackers connected to the router's LAN to execute OS command
injections.
nvd
CVE-2026-11739P3MEDIUMCVSS 6.4fixed in V1.1.0.222026-08-11
CVE-2026-11739 [MEDIUM] CWE-78 CVE-2026-11739: A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-ad
A command injection vulnerability in certain affected NETGEAR Nighthawk
devices allows a network-adjacent attacker with the ability to intercept
and modify local network traffic (attacker in the middle) to compromise
the confidentiality and integrity of the affected device.
nvd
CVE-2026-11735P4MEDIUMCVSS 4.9fixed in V1.1.0.222026-08-11
CVE-2026-11735 [MEDIUM] CWE-121 CVE-2026-11735: A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authentica
A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality.
nvd
CVE-2026-11736P4MEDIUMCVSS 4.9fixed in V1.1.0.222026-08-11
CVE-2026-11736 [MEDIUM] CWE-20 CVE-2026-11736: A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated
A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.
nvd
CVE-2026-9215P4MEDIUMCVSS 6.7fixed in V1.1.0.222026-09-08
CVE-2026-9215 [MEDIUM] CWE-352 CVE-2026-9215: A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker wh
A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality impact due to this vulnerability.
nvd
CVE-2026-0410P4MEDIUMCVSS 4.5fixed in V1.1.0.222026-06-09
CVE-2026-0410 [MEDIUM] CWE-20 CVE-2026-0410: Authenticated administrators connected to the local network can gain elevated access to the router
Authenticated administrators connected to the local network can gain
elevated access to the router and make unauthorized changes to router
software and functionality.
nvd