Impact
A flaw in the /www/cgi-bin/upgrade CGI on Netcore NBR200V2 allows manipulation of the QUERY_STRING parameter so that arbitrary shell commands are executed on the device. Based on the description, it is inferred that the attacker does not need authentication, which could give attackers full control over the underlying operating system, thus compromising confidentiality, integrity, and availability of the device and any associated network services.
Affected Systems
The vulnerability was identified in Netcore NBR200V2 firmware version 1.3.241127.071246. The likely attack vector involves remote interaction with the Firmware Upgrade CGI endpoint, which is typically exposed for remote firmware management.
Risk and Exploitability
The CVSS score of 9.4 indicates a critical impact level. The EPSS score is 2%, yet a publicly available exploit exists, increasing the likelihood of real‑world attacks. The vulnerability is not yet listed in CISA’s KEV catalog, but its high severity and remote nature mean that it could be actively exploited by malicious actors.
OpenCVE Enrichment