OS Command Injection Vulnerability in Netcore NBR200V2 Web Management Interface
CVE-2026-101001
Key Information:
Badges
What is CVE-2026-101001?
A critical vulnerability exists in the Netcore NBR200V2 router's Web Management Interface, specifically within the eval function of the network_tools component. This issue arises from improper handling of the QUERY_STRING parameter, allowing remote attackers to execute arbitrary operating system commands. The exploit method has been publicly released, and the vendor's lack of response to the advisory raises concerns about the urgency of applying necessary security patches. Users are strongly advised to take immediate action to mitigate the risk associated with this vulnerability.
Affected Version(s)
NBR200V2 1.3.241127.071246
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
