Command Injection Vulnerability in Netcore NBR200V2 LAN IP Configuration
CVE-2026-94096
Key Information:
Badges
What is CVE-2026-94096?
A command injection vulnerability exists in the LAN IP Configuration Handler of the Netcore NBR200V2 product. This vulnerability can be exploited by manipulating the 'ipv4' argument within the /usr/bin/network_tools file. Attackers can launch remote exploits, potentially affecting network integrity and security. The vendor has been notified but has not responded to mitigate the issue. Users of the affected version are advised to apply necessary security measures to prevent unauthorized command execution.
Affected Version(s)
NBR200V2 1.3.241127.071246
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
