Impact
The Netcore NBR200V2 firmware contains a command‑injection flaw in the LAN IP Configuration Handler’s network_tools utility. By manipulating the ipv4 argument, an attacker can execute arbitrary shell commands on the device. This weakness permits full control over the device’s operating system, exposing confidential data, enabling persistence, or enabling lateral movement.
Affected Systems
The vulnerability affects Netcore NBR200V2 devices running firmware 1.3.241127.071246. No other versions or products are currently listed as impacted.
Risk and Exploitability
With a CVSS score of 9.4 the risk is critical. The exploit is publicly available and can be launched remotely via the network without authentication. Although no EPSS score is published and the issue is not yet in the CISA KEV catalog, the public availability of an exploit, combined with the high severity, indicates a high likelihood of real‑world attacks against exposed devices.
OpenCVE Enrichment