Executive brief
Netcore NBR200V2 is a wireless router used for home and small office networking. An authenticated attacker can inject arbitrary shell commands through a crafted network ping request, executing commands with root privileges on the router. This could allow an attacker with valid web credentials to compromise the device, intercept network traffic, or pivot to other networks.
Technical details
The vulnerability is an OS command injection (CWE-78) in the Tools Ping Handler of /usr/bin/network_tools. The tools_ping ubus method passes an unsanitized url parameter directly into a system() call without proper escaping. An authenticated attacker can submit a specially crafted url parameter containing shell metacharacters to break out of the ping command template and execute arbitrary commands as root. A public exploit has been released.
Affected products
- Netcore NBR200V2 1.3.241127.071246
Timeline
- 2026-09-28: disclosed
- exploited: Public exploit released on GitHub