NETGEAR XR1000v2 OS Command Injection Vulnerability

Vulnerability

A vulnerability allowing OS command injection has been identified in the NETGEAR XR1000v2 router. This issue arises from insufficient input validation, enabling attackers connected to the router's LAN to execute arbitrary commands on the operating system.

Impact

Exploitation of this vulnerability allows for OS command injection, where an attacker can execute arbitrary commands on the router's operating system.

Remediation

Users can update their routers to firmware version 1.1.2.34 or later to address this vulnerability.

Added: Jan 13, 2026, 4:21 PM
Updated: Jan 13, 2026, 5:40 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
7.5
exploitability
3.5
remediation
7.7
relevance
2.0
threat
0.0
urgency
5.7
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.