Impact
A command injection flaw was discovered in the restore.cgi script of Netcore NBR200V2, allowing a remote attacker to craft a malicious QUERY_STRING that is executed by the underlying operating system. The vulnerability is theoretically exploitable from any network location that can reach the device, and the public exploit code has already been released, meaning an attacker could immediately attain remote code execution. An attacker capable of exploiting this flaw would gain full control of the affected device, compromising confidentiality, integrity, and availability of the system and any data it stores or forwards.
Affected Systems
The flaw is present in Netcore NBR200V2 version 1.3.241127.071246. The affected component is the Backup Restore service, whose restore.cgi endpoint processes query string arguments without proper validation or sanitization. No patch or fix has been released by Netcore, and the vendor’s response to the disclosure has been non‑existent. The product is identified by the CPE cpe:2.3:a:netcore:nbr200v2:*:*:*:*:*:*:*:* and is typically used in industrial control environments.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.4, indicating critical severity. Its EPSS score is not available and it is not listed in the CISA KEV catalog, but the public release of exploit code coupled with the lack of a vendor patch elevates the practical risk substantially. The exploitation path involves remote manipulation of the legacy QUERY_STRING parameter, so any external user with network access to the device can launch an attack. Given the high score and ease of exploitation, the risk to systems that remain unpatched is immediate and potentially catastrophic.
OpenCVE Enrichment