First published: Wed Feb 05 2025(Updated: )
NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR XR1000 firmware | <1.0.0.74 | |
Netgear XR1000v2 | <1.1.0.22 | |
NETGEAR XR500 firmware | <2.3.2.134 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25246 is considered a critical vulnerability due to its potential for remote code execution by unauthenticated users.
To fix CVE-2025-25246, update your NETGEAR XR1000, XR1000v2, or XR500 device to the latest firmware version available.
CVE-2025-25246 affects NETGEAR XR1000 before version 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134.
Yes, CVE-2025-25246 allows remote code execution by unauthenticated users, making it exploitable over the internet.
If you are using an affected NETGEAR device, it is crucial to apply the security patch as soon as possible to mitigate the risk.