Executive brief
Netcore NBR200V2 is a network router used to manage corporate and home network traffic. A command injection vulnerability in its traceroute diagnostic feature allows remote attackers to execute arbitrary commands on the device by manipulating the URL parameter, potentially leading to complete device compromise and network access for malicious purposes.
Technical details
A command injection vulnerability exists in the /usr/bin/network_tools utility within the traceroute diagnostic feature of Netcore NBR200V2. The vulnerability is triggered via the url argument and allows unauthenticated remote code execution. An attacker can inject shell commands into the url parameter to execute arbitrary commands on the affected device.
Affected products
- Netcore NBR200V2 1.3.241127.071246
Timeline
- 2026-09-21: disclosed: Vulnerability disclosed publicly