Description
A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4 results in command injection. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-20
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Netcore NBR200V2 firmware contains a command‑injection flaw in the LAN IP Configuration Handler’s network_tools utility. By manipulating the ipv4 argument, an attacker can execute arbitrary shell commands on the device. This weakness permits full control over the device’s operating system, exposing confidential data, enabling persistence, or enabling lateral movement.

Affected Systems

The vulnerability affects Netcore NBR200V2 devices running firmware 1.3.241127.071246. No other versions or products are currently listed as impacted.

Risk and Exploitability

With a CVSS score of 9.4 the risk is critical. The exploit is publicly available and can be launched remotely via the network without authentication. Although no EPSS score is published and the issue is not yet in the CISA KEV catalog, the public availability of an exploit, combined with the high severity, indicates a high likelihood of real‑world attacks against exposed devices.

Generated by OpenCVE AI on September 21, 2026 at 00:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor firmware release for NBR200V2 to eliminate the command injection flaw.
  • Configure network perimeter devices or firewall rules to block or restrict remote access to the LAN IP Configuration service and the /usr/bin/network_tools executable.
  • Continuously monitor system logs for unexpected command execution patterns or anomalous traffic to the device.
  • If an update cannot be applied immediately, isolate the device from the production network until remediation is completed.

Generated by OpenCVE AI on September 21, 2026 at 00:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4 results in command injection. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Netcore NBR200V2 LAN IP Configuration network_tools command injection
First Time appeared Netcore
Netcore nbr200v2
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:netcore:nbr200v2:*:*:*:*:*:*:*:*
Vendors & Products Netcore
Netcore nbr200v2
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Netcore Nbr200v2
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-20T23:30:12.665Z

Reserved: 2026-09-20T09:18:58.632Z

Link: CVE-2026-94096

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-21T00:16:59.617

Modified: 2026-09-21T00:16:59.617

Link: CVE-2026-94096

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:30:06Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')