Description
A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4 results in command injection. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-20
Score: 9.4 Critical
EPSS: 2.0% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Netcore NBR200V2 firmware contains a command‑injection flaw in the LAN IP Configuration Handler’s network_tools utility. By manipulating the ipv4 argument, an attacker can execute arbitrary shell commands on the device. This weakness permits full control over the device’s operating system, exposing confidential data, enabling persistence, or enabling lateral movement.

Affected Systems

The vulnerability affects Netcore NBR200V2 devices running firmware 1.3.241127.071246. No other versions or products are currently listed as impacted.

Risk and Exploitability

With a CVSS score of 9.4 the risk is critical. The exploit is publicly available and can be launched remotely via the network without authentication. The EPSS score of 2% indicates a low but nonzero exploitation probability, and the issue is not yet in the CISA KEV catalog; the public availability of an exploit, combined with the high severity, indicates a high likelihood of real‑world attacks against exposed devices.

Generated by OpenCVE AI on September 26, 2026 at 05:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest vendor firmware release for NBR200V2 to eliminate the command injection flaw.
  • Configure network perimeter devices or firewall rules to block or restrict remote access to the LAN IP Configuration service and the /usr/bin/network_tools executable.
  • Continuously monitor system logs for unexpected command execution patterns or anomalous traffic to the device.
  • If an update cannot be applied immediately, isolate the device from the production network until remediation is completed.

Generated by OpenCVE AI on September 26, 2026 at 05:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4 results in command injection. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Netcore NBR200V2 LAN IP Configuration network_tools command injection
First Time appeared Netcore
Netcore nbr200v2
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:netcore:nbr200v2:*:*:*:*:*:*:*:*
Vendors & Products Netcore
Netcore nbr200v2
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Netcore Nbr200v2
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T10:51:26.704Z

Reserved: 2026-09-20T09:18:58.632Z

Link: CVE-2026-94096

cve-icon Vulnrichment

Updated: 2026-09-21T10:51:09.073Z

cve-icon NVD

Status : Deferred

Published: 2026-09-21T00:16:59.617

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-94096

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T05:45:05Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')