Junglewise Threat Intelligence

CVE-2026-101001: Netcore NBR200V2 command injection in network_tools

CVE-2026-101001 · Severity: critical · CVSS 10 · Published 2026-09-28

Technologies: Netcore NBR200V2. Vendors: Netcore.

Executive brief

The Netcore NBR200V2 router contains a critical flaw in its web management interface that allows attackers to execute arbitrary system commands remotely without authentication. An attacker can craft a malicious HTTP request to gain complete control over the router, potentially compromising network traffic and enabling lateral attacks into connected networks. This vulnerability affects the router's ability to safely process diagnostic commands.

Technical details

The vulnerability is an unauthenticated OS command injection in the /www/cgi-bin/network_tools CGI script, where user-supplied QUERY_STRING input is passed directly to eval() before authentication checks occur. The vulnerable code path parses URL parameters using eval without proper sanitization, as the urldecode() sanitization function is commented out. An attacker can send a crafted GET request to execute arbitrary shell commands with root privileges on the device.

Affected products

  • Netcore NBR200V2 1.3.241127.071246

Timeline

  • 2026-09-28: disclosed
  • 2026-09-28: other: Exploit code published on GitHub

References

Related threats