Description
A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-21
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

A command injection flaw was discovered in the restore.cgi script of Netcore NBR200V2, allowing a remote attacker to craft a malicious QUERY_STRING that is executed by the underlying operating system. The vulnerability is theoretically exploitable from any network location that can reach the device, and the public exploit code has already been released, meaning an attacker could immediately attain remote code execution. An attacker capable of exploiting this flaw would gain full control of the affected device, compromising confidentiality, integrity, and availability of the system and any data it stores or forwards.

Affected Systems

The flaw is present in Netcore NBR200V2 version 1.3.241127.071246. The affected component is the Backup Restore service, whose restore.cgi endpoint processes query string arguments without proper validation or sanitization. No patch or fix has been released by Netcore, and the vendor’s response to the disclosure has been non‑existent. The product is identified by the CPE cpe:2.3:a:netcore:nbr200v2:*:*:*:*:*:*:*:* and is typically used in industrial control environments.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.4, indicating critical severity. Its EPSS score is not available and it is not listed in the CISA KEV catalog, but the public release of exploit code coupled with the lack of a vendor patch elevates the practical risk substantially. The exploitation path involves remote manipulation of the legacy QUERY_STRING parameter, so any external user with network access to the device can launch an attack. Given the high score and ease of exploitation, the risk to systems that remain unpatched is immediate and potentially catastrophic.

Generated by OpenCVE AI on September 21, 2026 at 01:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy any available firmware or security patch for Netcore NBR200V2 that fixes the restore.cgi command injection vulnerability.
  • Block or restrict external access to the device’s restore.cgi endpoint using firewall rules or router ACLs.
  • Disable the backup/restore function if it is not essential, or isolate the device from external networks through segmentation.
  • Continuously monitor system and web logs for anomalous access patterns to restore.cgi and investigate any suspicious activity.

Generated by OpenCVE AI on September 21, 2026 at 01:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title Netcore NBR200V2 Backup Restore restore.cgi command injection
First Time appeared Netcore
Netcore nbr200v2
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:netcore:nbr200v2:*:*:*:*:*:*:*:*
Vendors & Products Netcore
Netcore nbr200v2
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Netcore Nbr200v2
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T00:15:06.412Z

Reserved: 2026-09-20T09:19:09.259Z

Link: CVE-2026-94099

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-21T01:16:29.983

Modified: 2026-09-21T01:16:29.983

Link: CVE-2026-94099

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:15:03Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')