CVE-2025-25246

Published Feb 5, 2025

Last updated 2 months ago

Overview

Description
NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users.
Source
cve@mitre.org
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.1
Impact score
5.9
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

cve@mitre.org
CWE-94

Social media

Hype score
Not currently trending
  1. #Vulnerability #AccessPoints NETGEAR Patches Critical Security Vulnerabilities in WiFi Routers (CVE-2025-25246) and Access Points https://t.co/1DW1MNy0rY

    @Komodosec

    9 Mar 2025

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 👀 VulnWatch Monday: CVE-2025-25246 🔓 NETGEAR XR1000 (pre-1.0.0.74), XR1000v2 (pre-1.1.0.22) and XR500 (pre-2.3.2.134) routers are vulnerable to unauthorized access and remote code execution. 🔧 Fix: Download the latest firmware from @NETGEAR Support https://t.co/mpctytoS1F

    @kpoireault

    10 Feb 2025

    76 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2025-25246 (CVSS:8.1, HIGH) is Received. NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unau..https://t.co/tYrTNe0mw6 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    10 Feb 2025

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Threat Alert: NETGEAR Patches Critical Security Vulnerabilities in WiFi Routers (CVE-2025-2524 CVE-2025-25246 Severity: ⚠️ Critical Maturity: 💢 Emerging Learn more: https://t.co/XokKjKaxgb #CyberSecurity #ThreatIntel #InfoSec

    @fletch_ai

    8 Feb 2025

    63 Impressions

    1 Retweet

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  5. 🚨🚨NETGEAR Patches Critical Security Vulnerabilities in WiFi Routers (CVE-2025-25246) and Access Points ⚠️This vulnerability could allow an attacker to take complete control of the affected device without needing any login credentials. ZoomEye Dork👉app="NETGEAR XR1000" ||… htt

    @zoomeye_team

    8 Feb 2025

    393 Impressions

    1 Retweet

    5 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 NETGEAR Security Alert 🚨 Two critical vulnerabilities detected: 1️⃣ RCE (CVE-2025-25246, CVSS 9.8) • Affects: XR1000, XR1000v2, XR500 • Fixed firmware: XR1000 v1.0.0.74, XR1000v2 v1.1.0.22, XR500 v2.3.2.134 2️⃣ Auth Bypass (CVSS 9.6) • Affects: WAX206, WAX220, WAX214v2 •… h

    @GHak2learn27752

    7 Feb 2025

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. There is a new vulnerability with elevated criticality in NETGEAR XR1000 and other products (CVE-2025-25246) https://t.co/0ZJrNxmIoh

    @vuldb

    5 Feb 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. CVE-2025-25246 NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users. https://t.co/ukDxyoRPpk

    @CVEnew

    5 Feb 2025

    151 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes