Description
A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-20
Score: 10 Critical
EPSS: 2.9% Low
KEV: No
Impact: Remote Code Execution
Action: Assess Impact
AI Analysis

Impact

A command injection vulnerability exists in the CGI Diagnostic Endpoint /www/cgi-bin/network_tools of Netcore NBR200V2 firmware 1.3.241127.071246. Manipulating the argument param/key/val allows an attacker to inject arbitrary shell commands, potentially compromising device confidentiality, integrity, and availability. The weakness is reflected in CWE-74 and CWE-77.

Affected Systems

Netcore NBR200V2 devices running firmware version 1.3.241127.071246 are affected; the vulnerability is located in the /www/cgi-bin/network_tools CGI Diagnostic Endpoint component.

Risk and Exploitability

The CVSS score of 10 indicates critical severity. The EPSS score of 4% indicates a low but nonzero probability of exploitation. Despite the low probability, the vulnerability is publicly disclosed and remotely exploitable, indicating a high risk of exploitation. The vulnerability is not listed in the CISA KEV catalog as of the last update. An attacker can remotely trigger the CGI endpoint with crafted HTTP requests, leading to command execution on the device.

Generated by OpenCVE AI on September 25, 2026 at 01:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available firmware updates from Netcore that include a fix for the command injection in the CGI diagnostic endpoint.
  • If an update is unavailable, restrict access to the /www/cgi-bin/network_tools endpoint with network segmentation, firewall rules, or IP whitelisting to allow only trusted management traffic.
  • Disable or remove the CGI diagnostic endpoint if it is not required for operations to eliminate the attack surface.
  • Monitor system logs for abnormal HTTP requests or unexpected command execution patterns related to the CGI diagnostic endpoint.

Generated by OpenCVE AI on September 25, 2026 at 01:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title Netcore NBR200V2 CGI Diagnostic Endpoint network_tools command injection
First Time appeared Netcore
Netcore nbr200v2
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:netcore:nbr200v2:*:*:*:*:*:*:*:*
Vendors & Products Netcore
Netcore nbr200v2
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 10, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Netcore Nbr200v2
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-24T12:43:07.627Z

Reserved: 2026-09-20T09:19:01.953Z

Link: CVE-2026-94097

cve-icon Vulnrichment

Updated: 2026-09-24T12:43:03.014Z

cve-icon NVD

Status : Deferred

Published: 2026-09-21T00:16:59.793

Modified: 2026-09-24T13:17:17.460

Link: CVE-2026-94097

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T01:15:21Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')