Description
A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument url leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-20
Score: 9.4 Critical
EPSS: 2.4% Low
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a command injection flaw in the Traceroute Diagnostic Feature’s /usr/bin/network_tools binary on Netcore NBR200V2. By manipulating the url argument supplied to the binary, an attacker can cause the device to execute arbitrary shell commands. This can lead to compromise of confidentiality, integrity, and availability, allowing full control of the affected device. The weakness is typified by CWE-74 and CWE-77.

Affected Systems

The flaw exists in Netcore NBR200V2 firmware version 1.3.241127.071246. Devices running this exact firmware are directly vulnerable; no data indicates similar impacts on earlier firmware releases.

Risk and Exploitability

The CVSS score of 9.4 denotes critical severity. The EPSS score is 3%, indicating a low but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The CVE description explicitly states that the attack may be initiated remotely, confirming a remote exploitation vector. Public disclosure of exploit code suggests that an attacker could leverage this flaw without requiring local privileged access.

Generated by OpenCVE AI on September 25, 2026 at 01:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Netcore NBR200V2 firmware patch that fixes the command injection flaw as soon as it becomes available.
  • Disable or limit the Traceroute Diagnostic Feature, for example by blocking external access to the /usr/bin/network_tools interface or placing the device behind a firewall that denies the vulnerable endpoint.
  • Implement input validation or a whitelist on the url argument for the network_tools command to prevent injection, if the device allows configuration.
  • Monitor system logs and network traffic for anomalous command executions or suspicious connections to the device.

Generated by OpenCVE AI on September 25, 2026 at 01:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument url leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Netcore NBR200V2 Traceroute Diagnostic Feature network_tools command injection
First Time appeared Netcore
Netcore nbr200v2
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:netcore:nbr200v2:*:*:*:*:*:*:*:*
Vendors & Products Netcore
Netcore nbr200v2
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Netcore Nbr200v2
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T19:39:17.603Z

Reserved: 2026-09-20T09:18:55.221Z

Link: CVE-2026-94095

cve-icon Vulnrichment

Updated: 2026-09-21T19:39:13.767Z

cve-icon NVD

Status : Deferred

Published: 2026-09-21T00:16:59.440

Modified: 2026-09-21T20:17:40.513

Link: CVE-2026-94095

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T01:30:20Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')