Impact
The vulnerability resides in the setTools function of the /bin/netis.cgi diagnostic tool on Netcore Power 15AX devices. Manipulating the IpAddr argument allows an attacker to inject arbitrary operating‑system commands, resulting in remote command execution. This weakness corresponds to CWE‑77 (OS Command Injection) and CWE‑78 (Improper Neutralization of Special Elements used in an OS Command). The impact is that a remote attacker could gain full control over the device, compromising confidentiality, integrity, and availability.
Affected Systems
Affected firmware versions of Netcore Power 15AX are those up to and including 3.0.0.6938. Any device running these firmware images is vulnerable. The vulnerability is limited to the Diagnostic Tool Interface component; other product components are not affected.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. Although EPSS data is not provided, the existence of a publicly released exploit and the vendor’s lack of a timely response increase the risk of exploitation. Remote exploitation is possible over the network via the exposed Diagnostic Tool Interface. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment