Impact
The vulnerability is a command injection flaw in the Traceroute Diagnostic Feature’s /usr/bin/network_tools binary on Netcore NBR200V2. By manipulating the url argument supplied to the binary, an attacker can cause the device to execute arbitrary shell commands. This can lead to compromise of confidentiality, integrity, and availability, allowing full control of the affected device. The weakness is typified by CWE-74 and CWE-77.
Affected Systems
The flaw exists in Netcore NBR200V2 firmware version 1.3.241127.071246. Devices running this exact firmware are directly vulnerable; no data indicates similar impacts on earlier firmware releases.
Risk and Exploitability
The CVSS score of 9.4 denotes critical severity. The EPSS score is 3%, indicating a low but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The CVE description explicitly states that the attack may be initiated remotely, confirming a remote exploitation vector. Public disclosure of exploit code suggests that an attacker could leverage this flaw without requiring local privileged access.
OpenCVE Enrichment