Command Injection Vulnerability in Netcore NBR200V2 Routers
CVE-2026-94097
Key Information:
Badges
What is CVE-2026-94097?
A command injection vulnerability exists in the Netcore NBR200V2 router's CGI Diagnostic Endpoint. This flaw allows an attacker to manipulate the parameters, potentially executing unauthorized commands on the system remotely. The issue was found in the file located at /www/cgi-bin/network_tools, and its exploitation can lead to critical security breaches. Despite the vendor being notified of the problem, there has been no response regarding remediation, making it essential for users to assess their exposure and take appropriate protective measures.
Affected Version(s)
NBR200V2 1.3.241127.071246
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
