Impact
A flaw in the /www/cgi-bin/upgrade CGI on Netcore NBR200V2 allows an unauthenticated user to manipulate the QUERY_STRING parameter so that arbitrary shell commands are executed on the device. The vulnerability is a classic command injection, giving attackers full control over the underlying operating system, thus compromising confidentiality, integrity, and availability of the device and any associated network services.
Affected Systems
The vulnerability was identified in Netcore NBR200V2 firmware version 1.3.241127.071246. The attack vector relies on interacting with the Firmware Upgrade CGI endpoint, which is typically exposed for remote firmware management.
Risk and Exploitability
The CVSS score of 9.4 indicates a critical impact level. The EPSS score is not available, yet a publicly available exploit exists, increasing the likelihood of real‑world attacks. The vulnerability is not yet listed in CISA’s KEV catalog, but its high severity and remote nature mean that it could be actively exploited by malicious actors.
OpenCVE Enrichment