Executive brief
The Netcore NBR200V2 router contains a critical flaw in its web management interface that allows attackers to execute arbitrary system commands remotely without authentication. An attacker can craft a malicious HTTP request to gain complete control over the router, potentially compromising network traffic and enabling lateral attacks into connected networks. This vulnerability affects the router's ability to safely process diagnostic commands.
Technical details
The vulnerability is an unauthenticated OS command injection in the /www/cgi-bin/network_tools CGI script, where user-supplied QUERY_STRING input is passed directly to eval() before authentication checks occur. The vulnerable code path parses URL parameters using eval without proper sanitization, as the urldecode() sanitization function is commented out. An attacker can send a crafted GET request to execute arbitrary shell commands with root privileges on the device.
Affected products
- Netcore NBR200V2 1.3.241127.071246
Timeline
- 2026-09-28: disclosed
- 2026-09-28: other: Exploit code published on GitHub