← Browse

CVE-2026-9215

Low

No strong exploitation signal.

CVSS base
6.7 MEDIUM
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
EPSS — probability of exploitation (30 days)
0.1%
2.3th percentile
CISA KEV
Not listed
Weakness / dates
CWE-352
Published 2026-09-08 · modified 2026-09-11

CVSS breakdown

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H

Attack VectorAAdjacent
Attack ComplexityLLow
Privileges RequiredLLow
User InteractionRRequired
ScopeUUnchanged
ConfidentialityNNone
IntegrityHHigh
AvailabilityHHigh

Timeline

Description

A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality impact due to this vulnerability.

Affected

netgear

References

Official: NVD · CVE.org