Impact
A command injection vulnerability exists in the CGI Diagnostic Endpoint /www/cgi-bin/network_tools of Netcore NBR200V2 firmware 1.3.241127.071246. Manipulating the argument param/key/val allows an attacker to inject arbitrary shell commands, potentially compromising device confidentiality, integrity, and availability. The weakness is reflected in CWE-74 and CWE-77.
Affected Systems
Netcore NBR200V2 devices running firmware version 1.3.241127.071246 are affected; the vulnerability is located in the /www/cgi-bin/network_tools CGI Diagnostic Endpoint component.
Risk and Exploitability
The CVSS score of 10 indicates critical severity. The EPSS score of 4% indicates a low but nonzero probability of exploitation. Despite the low probability, the vulnerability is publicly disclosed and remotely exploitable, indicating a high risk of exploitation. The vulnerability is not listed in the CISA KEV catalog as of the last update. An attacker can remotely trigger the CGI endpoint with crafted HTTP requests, leading to command execution on the device.
OpenCVE Enrichment