CVE-2025-25246

Published Feb 5, 2025

Last updated 18 days ago

Overview

Description
NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users.
Source
cve@mitre.org
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.1
Impact score
5.9
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

cve@mitre.org
CWE-94

Social media

Hype score
Not currently trending
  1. 👀 VulnWatch Monday: CVE-2025-25246 🔓 NETGEAR XR1000 (pre-1.0.0.74), XR1000v2 (pre-1.1.0.22) and XR500 (pre-2.3.2.134) routers are vulnerable to unauthorized access and remote code execution. 🔧 Fix: Download the latest firmware from @NETGEAR Support https://t.co/mpctytoS1F

    @kpoireault

    10 Feb 2025

    76 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-25246 (CVSS:8.1, HIGH) is Received. NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unau..https://t.co/tYrTNe0mw6 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    10 Feb 2025

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Threat Alert: NETGEAR Patches Critical Security Vulnerabilities in WiFi Routers (CVE-2025-2524 CVE-2025-25246 Severity: ⚠️ Critical Maturity: 💢 Emerging Learn more: https://t.co/XokKjKaxgb #CyberSecurity #ThreatIntel #InfoSec

    @fletch_ai

    8 Feb 2025

    63 Impressions

    1 Retweet

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  4. 🚨🚨NETGEAR Patches Critical Security Vulnerabilities in WiFi Routers (CVE-2025-25246) and Access Points ⚠️This vulnerability could allow an attacker to take complete control of the affected device without needing any login credentials. ZoomEye Dork👉app="NETGEAR XR1000" ||… htt

    @zoomeye_team

    8 Feb 2025

    393 Impressions

    1 Retweet

    5 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 NETGEAR Security Alert 🚨 Two critical vulnerabilities detected: 1️⃣ RCE (CVE-2025-25246, CVSS 9.8) • Affects: XR1000, XR1000v2, XR500 • Fixed firmware: XR1000 v1.0.0.74, XR1000v2 v1.1.0.22, XR500 v2.3.2.134 2️⃣ Auth Bypass (CVSS 9.6) • Affects: WAX206, WAX220, WAX214v2 •… h

    @GHak2learn27752

    7 Feb 2025

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. There is a new vulnerability with elevated criticality in NETGEAR XR1000 and other products (CVE-2025-25246) https://t.co/0ZJrNxmIoh

    @vuldb

    5 Feb 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2025-25246 NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users. https://t.co/ukDxyoRPpk

    @CVEnew

    5 Feb 2025

    151 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes