Skip to finding
important · Wi-Fi — NETGEAR

A malicious website can make an authenticated NETGEAR administrator alter router configuration.

Affects

NETGEAR XR1000, XR1000v2, and XR500 gaming routers, embedded network appliances.

An administrator with an active management session must interact with attacker-controlled content, after which cross-site request forgery submits configuration changes with the administrator’s authority.

Detail and 1 source

NETGEAR lists affected models and fixed firmware releases.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 12, 2026