Netgear Xr1000v2 Firmware — known CVE vulnerabilities
Every CVE whose affected-product data names Netgear Xr1000v2 Firmware, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (6)
CVE-2026-0406 — CVSS 8.0 (high): An insufficient input validation vulnerability in the NETGEAR XR1000v2 allows attackers connected to the router's LAN to execute OS command…
CVE-2026-9215 — CVSS 6.7 (medium): A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering…
CVE-2026-11739 — CVSS 6.4 (medium): A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to…
CVE-2026-11735 — CVSS 4.9 (medium): A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized…
CVE-2026-11736 — CVSS 4.9 (medium): A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized…
CVE-2026-0410 — CVSS 4.5 (medium): Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router…